CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVSS
6.5
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Aug 18, 2026 · Last modified: Aug 20, 2026 · CWE-288
0.3%EPSS · 30 days0.3%
2026-08-192026-09-07
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-835278.1 HIG—
———An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.5hCVE-2026-77103——
———CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.7hCVE-2026-626508.8 HIG—
——0A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.3hCVE-2026-761697.5 HIG42.8%
——13fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.2hCVE-2026-629169.1 CRI45.7%
——14Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.4hCVE-2026-847777.4 HIG14.9%
——4Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.5d