CWE-565— Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.— MITRE CWE catalog
82 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-565page 1 of 2
- CVE-2026-0257CRITICALCVSS 7.8EG 9.1⚠ KEV2026-05-13
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGF…
- CVE-2023-41084CRITICALCVSS 9.8EG 10.02023-09-18
Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.
- CVE-2026-85181CRITICALCVSS 9.8EG 9.82026-09-03
CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and…
- CVE-2026-39324CRITICALCVSS 9.8EG 9.82026-04-07
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls ba…
- CVE-2014-125112CRITICALCVSS 9.8EG 9.82026-03-26
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on…
- CVE-2022-50926CRITICALCVSS 9.8EG 9.82026-01-13
WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user …
- CVE-2025-65212CRITICALCVSS 9.8EG 9.82026-01-06
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and dow…
- CVE-2025-14440CRITICALCVSS 9.8EG 9.82025-12-13
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with t…
- CVE-2025-59247CRITICALCVSS 9.8EG 9.82025-10-09
Azure PlayFab Elevation of Privilege Vulnerability
- CVE-2025-2395CRITICALCVSS 9.8EG 9.82025-03-17
The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.
- CVE-2024-0947CRITICALCVSS 9.8EG 9.82024-06-27
Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Cl…
- CVE-2024-28288CRITICALCVSS 9.8EG 9.82024-03-30
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business…
- CVE-2023-35885CRITICALCVSS 9.8EG 9.82023-06-20
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
- CVE-2023-3050CRITICALCVSS 9.8EG 9.82023-06-13
Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15.
- CVE-2022-38297CRITICALCVSS 9.8EG 9.82022-09-12
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
- CVE-2021-28171CRITICALCVSS 9.8EG 9.82021-04-06
The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.
- CVE-2021-29012CRITICALCVSS 9.8EG 9.82021-04-02
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is…
- CVE-2019-7266CRITICALCVSS 9.8EG 9.82019-07-02
Linear eMerge 50P/5000P devices allow Authentication Bypass.
- CVE-2018-20512CRITICALCVSS 9.8EG 9.82019-01-03
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
- CVE-2018-5190CRITICALCVSS 9.8EG 9.82018-04-17
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified cookie, related to pc_head.php, pc_login.php, and pc_login_page.php.
- CVE-2018-5455CRITICALCVSS 9.8EG 9.82018-03-05
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an at…
- CVE-2017-7279CRITICALCVSS 9.8EG 9.82017-04-12
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.
- CVE-2023-32725CRITICALCVSS 9.6EG 9.62023-12-18
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
- CVE-2026-76186CRITICALCVSS 9.1EG 9.12026-09-16
Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate…
- CVE-2022-22785CRITICALCVSS 5.9EG 9.12022-05-18
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsusp…
- CVE-2026-5130HIGHCVSS 8.8EG 8.82026-03-30
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_troubleshoot_simulate_user cookie value dire…
- CVE-2024-9970HIGHCVSS 8.8EG 8.82024-10-15
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
- CVE-2024-22186HIGHCVSS 8.8EG 8.82024-04-18
The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.
- CVE-2023-45141HIGHCVSS 8.8EG 8.82023-10-16
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests on behalf of a user.…
- CVE-2023-45128HIGHCVSS 8.8EG 8.82023-10-16
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf …
- CVE-2021-33842HIGHCVSS 8.8EG 8.82021-06-09
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be w…
- CVE-2012-5631HIGHCVSS 8.8EG 8.82019-11-25
ipa 3.0 does not properly check server identity before sending credential containing cookies
- CVE-2017-6896HIGHCVSS 8.8EG 8.82017-03-14
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.
- CVE-2022-30620HIGHCVSS 8.2EG 8.82022-07-18
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows ch…
- CVE-2016-15002HIGHCVSS 7.3EG 8.82022-06-09
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is…
- CVE-2021-47706HIGHCVSS 8.7EG 8.72025-12-09
COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting …
- CVE-2024-55211HIGHCVSS 8.4EG 8.42025-04-17
An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
- CVE-2026-75757HIGHCVSS 8.3EG 8.32026-08-31
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin…
- CVE-2021-41263HIGHCVSS 8.3EG 8.32021-11-15
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application ma…
- CVE-2026-53871HIGHCVSS 8.1EG 8.12026-06-17
Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_prof…
- CVE-2025-64447HIGHCVSS 8.1EG 8.12025-12-09
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.…
- CVE-2024-28233HIGHCVSS 8.1EG 8.12024-03-27
JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of Jupyte…
- CVE-2022-29248HIGHCVSS 8.0EG 8.02022-05-25
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cook…
- CVE-2021-36338HIGHCVSS 6.3EG 8.02022-01-21
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not hav…
- CVE-2024-21872HIGHCVSS 7.5EG 7.52024-04-18
The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages that allows more critical operations to the transmitter.
- CVE-2022-35284HIGHCVSS 7.5EG 7.52022-07-25
IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 230811.
- CVE-2021-41819HIGHCVSS 7.5EG 7.52022-01-01
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
- CVE-2019-17104HIGHCVSS 7.5EG 7.52019-10-08
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
- CVE-2018-19224HIGHCVSS 7.5EG 7.52018-11-12
An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.
- CVE-2023-32612HIGHCVSS 7.2EG 7.22023-06-30
Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.
Map vulnerabilities like CWE-565 to your infrastructure
EchelonGraph correlates every CVE — across CWE-565 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →