The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
Volume of CVEs assigned to CWE-302 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43441CRITICAL Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.
This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0.
Users are recommend | Dec 24, 2024 | 9.8 | 79 | NO | YES |
CVE-2026-47303HIGH Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-50528HIGH Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 8.2 | 36 | NO | NO |
CVE-2025-63210CRITICAL The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifyin | Nov 19, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-48781CRITICAL Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the | Jun 16, 2026 | 9.9 | 33 | NO | NO |
CVE-2025-29813CRITICAL Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | May 8, 2025 | 9.8 | 32 | NO | NO |
CVE-2024-4024HIGH An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16. | Apr 25, 2024 | 8.8 | 31 | NO | NO |
CVE-2026-39429CRITICAL kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by | Apr 8, 2026 | 9.1 | 30 | NO | NO |
CVE-2023-4612CRITICAL Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS | Nov 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-56404CRITICAL In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected. | Jan 24, 2025 | 9.9 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.