Every story tagged Authentication Vulnerability, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
6 stories · open in the command center
CVE-2026-69110 is a critical authentication bypass vulnerability (CVSS 9.3) in OpenCode Studio versions before 2.4.4 that allows unauthenticated attackers to read arbitrary files and delete videos, exposing sensitive user data and creating significant data breach and integrity risks. IT organizations must immediately identify all deployments of affected versions and establish an urgent patching protocol, as this vulnerability is easily exploitable with public proof-of-concept code available. This incident underscores the need for enhanced API security assessments, zero-trust architecture implementation, and strengthened vendor risk management processes across the organization.
CVE-2026-70478 is a critical vulnerability (CVSS 9.2) in Flowise versions prior to 3.1.3 that allows unauthenticated attackers to access OAuth credentials and refresh tokens without authentication, potentially compromising connected services and exhausting refresh-token quotas. Organizations using Flowise for LLM workflow automation face immediate risk of unauthorized access to integrated third-party services and credential abuse. IT leaders must prioritize immediate patching to version 3.1.3 and conduct a security audit of any OAuth-connected services to identify potential compromise.
CVE-2026-70482 is a critical authentication bypass vulnerability (CVSS 8.1) in Open WebUI versions 0.8.0-0.11.0 that allows unauthorized users to hijack sessions by exchanging OAuth tokens from any client registered with the same provider, potentially enabling account takeover and data breach. This vulnerability poses significant risk to organizations using self-hosted AI platforms with OAuth enabled, as attackers can impersonate legitimate users without authorization. IT leaders must immediately assess deployment scope and implement mitigation strategies to prevent unauthorized access to AI systems and sensitive data.
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only from the request body and falls back to the caller's active organization from their session. When these differ, an authenticated member of multiple organizations can perform subscription actions (cancel, change plan, restore, billing portal access) against an organization they belong to but should not manage, and can access another organization's billing details including payment methods, invoices, and subscription state.
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username collision with an Administrator account and obtain administrative privileges by logging in with their own password while the session loads the Administrator's account data.