Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-289
Weakness type CWE-289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 21 | 0 |
Monthly trend
▂▁▂▁▂▂▇▅▆█▁
2025-12 1 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 5 · 2026-07 3 · 2026-08 4 · 2026-09 6 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48618 | 6.5 | 87.8 | — | — |
| CVE-2026-44492 | 8.6 | 54.5 | — | Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PRO… |
| CVE-2026-50627 | 9.1 | 54.2 | — | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator |
| CVE-2026-8457 | 9.8 | 51.7 | — | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged … |
| CVE-2026-56091 | 8.2 | 50.2 | — | Apache Shiro: Authentication bypass in Guice-Web integration |
| CVE-2026-53622 | 7.8 | 48.3 | — | Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case… |
| CVE-2026-3184 | 5.3 | 47.9 | — | Util-linux: util-linux: access control bypass due to improper hostname canonicalization |
| CVE-2026-73511 | 5.3 | 44.3 | — | Envoy: Potential path-matching/authentication bypass when using Envoy in combination wi… |
| CVE-2026-10842 | 7.5 | 42.6 | — | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected … |
| CVE-2026-9701 | 9.8 | 39.3 | — | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escal… |
| CVE-2026-55075 | 7.4 | 39.1 | — | Coder vulnerable to OIDC account takeover via email-based user matching and email_verif… |
| CVE-2026-32639 | 6.8 | 37.6 | — | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions … |
| CVE-2026-15980 | 9.8 | 37.2 | — | MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token |
| CVE-2026-76183 | 9.8 | 30.7 | — | Apache Tomcat: Bypass of security constraints for WebSocket endpoints |
| CVE-2026-23903 | 5.3 | 27.0 | — | Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems |
| CVE-2025-14777 | 6.0 | 25.7 | — | Keycloak: keycloak idor in realm client creating/deleting |
| CVE-2026-15985 | 8.1 | 23.3 | — | Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authenticati… |
| CVE-2026-43617 | 6.3 | 22.2 | — | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution |
| CVE-2026-12101 | 8.1 | 17.7 | — | Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Secu… |
| CVE-2026-92579 | 5.3 | 17.5 | — | AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 4 |
| ibm | 2 |
| red hat | 2 |
| axios | 1 |
| coder | 1 |
| envoyproxy | 1 |
| joe007 | 1 |
| netgsm | 1 |
| nodejs | 1 |
| python-social-auth | 1 |
| radiustheme | 1 |
| rsyncproject | 1 |
| tangiblewp | 1 |
| traefik | 1 |
| wintercms | 1 |