CVE-2026-28148
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVSS
9.8
Critical
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Published: Aug 13, 2026 · Last modified: Aug 14, 2026 · CWE-347
0.2%EPSS · 30 days0.2%
2026-08-142026-08-26
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-75946—0.1%
——0A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.6dCVE-2026-687458.1 HIG1.5%
——0Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures.
Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.3dCVE-2026-628349.3 CRI21.4%
——6Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.3dCVE-2026-728615.8 MED9.8%
——3The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await verify(...))", so when the X-Hub-Signature-256 header is absent the first operand is true, the logical OR short-circuits, and the function reports success without performing any HMAC verification. main.js rejects a request only when verifyWebhook returns false, so an unauthenticated request carrying no signature passes the check. Processing then continues to postComment, which takes the repository and issue objects directly from the request body, letting the caller direct the deployed function to post a comment on a repository and issue of their choosing using the configured GITHUB_TOKEN, with the issue author login from the body interpolated into the comment text.6dCVE-2026-195059.8 CRI9.8%
——3Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.3hCVE-2026-762347.5 HIG12.8%
——4libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for imported X25519 secret keys); libcrux-ed25519 performed a duplicated clamping step during key generation; and libcrux-psq panicked instead of propagating an AEADError. These were fixed in the respective patched releases.6d