#authbypass

6 posts · Last used 2d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 2d ago
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation. #Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow http://securityonline.info/konnectivity-vulnerability-cve-2026-16242/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 15, 2026
Two critical RabbitMQ flaws allow authentication bypass. One forges TLS client certs; the other tricks OAuth2 JWKS to accept any JWT. #RabbitMQ #AuthBypass #TLS #OAuth2 #InfoSec https://securityonline.info/rabbitmq-authentication-bypass-flaws/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 11, 2026
Three Apache IoTDB vulnerabilities include a critical path traversal (CVE-2026-24014) and an authentication bypass. Upgrade to 2.0.8 now. #ApacheIoTDB #PathTraversal #AuthBypass #CVE #IoTSecurity #InfoSec https://securityonline.info/apache-iotdb-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 10, 2026
🤖 Actively exploited: critical auth bypass in Gitea Docker image. Attackers can impersonate any user, including admins. Patch available. 🔗 https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-auth-bypass-in-gitea-docker-image/ #CVE #AuthBypass #CyberSec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 09, 2026
Five Apache Camel vulnerabilities enable server-side request forgery and a Keycloak authentication bypass. Upgrade to 4.21.0, 4.18.3, or 4.14.8. #ApacheCamel #SSRF #AuthBypass #Deserialization #Keycloak #InfoSec https://meterpreter.org/apache-camel-five-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 07, 2026
🤖 CVE-2026-40138 (CVSS 9.2): Critical pre-authentication bypass in BeyondTrust Remote Support & Privileged Remote Access. Unauthenticated attackers can fully compromise vulnerable enterprise devices. CVE-2026-40139 (CVSS 8.5) also disclosed. Patches available. 🔗 https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html #CVE #AuthBypass #RemoteAccess #CyberSec
0
0
0

You've seen all posts