The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
Volume of CVEs assigned to CWE-565 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0257CRITICAL Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establi | May 13, 2026 | 9.1 | 98 | YES | YES |
CVE-2023-35885CRITICAL CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | Jun 20, 2023 | 9.8 | 81 | NO | YES |
CVE-2017-6896HIGH Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Bas | Mar 14, 2017 | 8.8 | 39 | NO | YES |
CVE-2025-65212CRITICAL An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker | Jan 6, 2026 | 9.8 | 37 | NO | NO |
CVE-2008-5784CRITICAL V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | Dec 31, 2008 | 9.8 | 37 | NO | YES |
CVE-2025-59247CRITICAL Azure PlayFab Elevation of Privilege Vulnerability | Oct 9, 2025 | 9.8 | 35 | NO | NO |
CVE-2022-50926CRITICAL WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's ' | Jan 13, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14440CRITICAL The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in t | Dec 13, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-39324CRITICAL Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secret | Apr 7, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-53871HIGH Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile | Jun 17, 2026 | 8.1 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.