#Auth Bypass
All CosmicBytez Labs articles tagged #Auth Bypass, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-18248: Fastify AWS Lambda Auth Bypass Allows Privilege Escalation
A critical vulnerability in @fastify/aws-lambda 6.4.0 allows attackers to spoof AWS API Gateway authorizer claims by sending crafted HTTP headers,...
- Security
CVE-2026-41452: Krayin CRM Admin Account Takeover via Installer Middleware Bypass
A critical missing authentication vulnerability in Krayin CRM 2.2.4 allows unauthenticated attackers to overwrite the primary administrator account by...
- News
Gitea Vulnerability Exposes Private Container Images without Authentication
A Gitea flaw lets unauthenticated remote attackers pull private container images from self-hosted deployments with no account or credentials required.
- News
Hackers Exploit RCE Flaws in Qinglong Task Scheduler for Cryptomining
Threat actors are actively exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptomining...
- Security
Snap One WattBox 800/820 Diagnostic Auth Bypass
A CVSS 9.8 critical vulnerability in Snap One WattBox 800 and 820 series firmware exposes undisclosed diagnostic HTTP endpoints protected only by the...