CWE-807— Reliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.— MITRE CWE catalog
118 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-807page 2 of 3
- CVE-2026-20849HIGHCVSS 7.5EG 7.52026-01-13
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
- CVE-2025-66507HIGHCVSS 7.5EG 7.52025-12-09
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previou…
- CVE-2025-59152HIGHCVSS 7.5EG 7.52025-10-06
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined…
- CVE-2024-51561HIGHCVSS 7.5EG 7.52024-11-04
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchang…
- CVE-2022-24400HIGHCVSS 7.5EG 7.52023-10-19
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.
- CVE-2026-88004HIGHCVSS 7.4EG 7.42026-09-10
Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an …
- CVE-2026-56681HIGHCVSS 7.3EG 7.32026-09-22
9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when isL…
- CVE-2026-41390HIGHCVSS 7.3EG 7.32026-04-28
OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. Attackers can obtain user approval for one wrappe…
- CVE-2026-41380HIGHCVSS 7.3EG 7.32026-04-28
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional ca…
- CVE-2025-10161HIGHCVSS 7.3EG 7.32025-11-11
Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on Untrusted Inputs in a Security Decision vulnerability in Turkguven Software Technologies Inc. Perfektive allows Brute F…
- CVE-2024-11146HIGHCVSS 6.3EG 7.32025-01-17
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application. P…
- CVE-2026-102117HIGHCVSS 7.2EG 7.22026-09-30
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection t…
- CVE-2026-87858HIGHCVSS 7.2EG 7.22026-09-21
Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL …
- CVE-2026-41299HIGHCVSS 7.1EG 7.12026-04-21
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorizatio…
- CVE-2026-32057HIGHCVSS 7.1EG 7.12026-03-21
OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts client.id=control-ui without proper device identity verification. An authenticated node role…
- CVE-2025-0117HIGHCVSS 7.1EG 7.12025-03-12
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProte…
- CVE-2023-46686HIGHCVSS 7.1EG 7.12023-12-18
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagn…
- CVE-2025-53717HIGHCVSS 7.0EG 7.02025-10-14
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- CVE-2021-29479HIGHCVSS 7.0EG 7.02021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` header can be used to perform cache poisoning of a cache fronting a Ratpack server if the cache key does not include the `X-…
- CVE-2026-79701MEDIUMCVSS 6.9EG 6.92026-09-14
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 5.6.1p2 and 6.0.0 - 6.9.0 - In the ajax_contact, optin_form and form_builder…
- CVE-2026-79700MEDIUMCVSS 6.9EG 6.92026-09-14
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag fro…
- CVE-2026-0390MEDIUMCVSS 6.7EG 6.72026-04-14
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- CVE-2026-59157MEDIUMCVSS 6.5EG 6.52026-09-09
webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsT…
- CVE-2026-18705MEDIUMCVSS 6.5EG 6.52026-08-11
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient…
- CVE-2025-65328MEDIUMCVSS 6.5EG 6.52026-01-05
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without validating a trusted proxy chain. An attacker can supply an arbitrary XFF value in a remote request to spoof …
- CVE-2025-55736MEDIUMCVSS 6.5EG 6.52025-08-19
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
- CVE-2024-52327MEDIUMCVSS 6.5EG 6.52025-01-23
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
- CVE-2022-20744MEDIUMCVSS 6.5EG 6.52022-05-03
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protecti…
- CVE-2026-48980MEDIUMCVSS 6.3EG 6.32026-06-18
pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injection into local-check logic. These environ…
- CVE-2026-39807MEDIUMCVSS 6.3EG 6.32026-05-01
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex retur…
- CVE-2024-47254MEDIUMCVSS 6.3EG 6.32024-11-05
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain root access to the system.
- CVE-2019-25711MEDIUMCVSS 6.2EG 6.22026-04-12
SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payloa…
- CVE-2019-25594MEDIUMCVSS 6.2EG 6.22026-03-22
ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the tab…
- CVE-2019-25544MEDIUMCVSS 5.5EG 6.22026-03-21
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the …
- CVE-2024-9310MEDIUMCVSS 6.0EG 6.02025-01-22
By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data can be transmitted to aircraft targets. This can lead to the appearance of fake aircraft on displays and potentially t…
- CVE-2026-76147MEDIUMCVSS 5.9EG 5.92026-10-01
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
- CVE-2026-35670MEDIUMCVSS 5.9EG 5.92026-04-10
OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploiting mutable username matching instead of stable numeric user identifiers. Attackers can ma…
- CVE-2026-35655MEDIUMCVSS 5.7EG 5.72026-04-10
OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicting tool identity hints from rawInput and metadata. Attackers can spoof tool identities through rawInput parameters to s…
- CVE-2019-25621MEDIUMCVSS 5.5EG 5.52026-03-23
Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary ch…
- CVE-2026-19579MEDIUMCVSS 5.4EG 5.42026-08-11
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments an…
- CVE-2026-16093MEDIUMCVSS 5.4EG 5.42026-07-17
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with …
- CVE-2026-53860MEDIUMCVSS 5.4EG 5.42026-06-16
OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender identity. Attackers can influence conversatio…
- CVE-2026-32898MEDIUMCVSS 5.4EG 5.42026-03-21
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive a…
- CVE-2025-55735MEDIUMCVSS 5.4EG 5.42025-08-19
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post u…
- CVE-2024-21510MEDIUMCVSS 5.4EG 5.42024-11-01
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an O…
- CVE-2026-56682MEDIUMCVSS 5.3EG 5.32026-09-22
9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, ch…
- CVE-2026-78427MEDIUMCVSS 5.3EG 5.32026-09-17
The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any u…
- CVE-2026-85602MEDIUMCVSS 5.3EG 5.32026-09-04
The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an …
- CVE-2026-12058MEDIUMCVSS 5.3EG 5.32026-06-12
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
- CVE-2026-29794MEDIUMCVSS 5.3EG 5.32026-03-20
Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unauthenticated users are able to bypass the application's built-in rate-limits by spoofing the `X-Forwarded-For` or `X-Rea…
Map vulnerabilities like CWE-807 to your infrastructure
EchelonGraph correlates every CVE — across CWE-807 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →