Known Vulnerabilities for User Account And Authentication by Cloudfoundry

Listed below are 9 of the newest known vulnerabilities associated with "User Account And Authentication" by "Cloudfoundry".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-67351 json Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loa... Not Provided 2026-07-30 2026-07-31
CVE-2026-67334 json better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints... Not Provided 2026-08-01 2026-08-03
CVE-2026-66884 json Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) ... Not Provided 2026-08-04 2026-08-04
CVE-2026-63238 json An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including... Not Provided 2026-07-29 2026-07-29
CVE-2026-61609 json Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter def... Not Provided 2026-07-28 2026-07-28
CVE-2026-60104 json Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the au... Not Provided 2026-07-08 2026-07-14
CVE-2026-59151 json Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted i... Not Provided 2026-07-10 2026-07-13
CVE-2026-57848 json Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via... Not Provided 2026-07-18 2026-07-20
CVE-2026-56453 json HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept ... Not Provided 2026-07-16 2026-07-16
CVE-2026-56450 json AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached t... Not Provided 2026-06-22 2026-06-22

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCloudfoundryUser Account And Authentication74.9.0
ApplicationCloudfoundryUser Account And Authentication74.8.0
ApplicationCloudfoundryUser Account And Authentication74.3.0
ApplicationCloudfoundryUser Account And Authentication74.2.0
ApplicationCloudfoundryUser Account And Authentication74.12.0
ApplicationCloudfoundryUser Account And Authentication74.11.0
ApplicationCloudfoundryUser Account And Authentication74.10.0
ApplicationCloudfoundryUser Account And Authentication74.1.0
ApplicationCloudfoundryUser Account And Authentication74.0.0
ApplicationCloudfoundryUser Account And Authentication73.7.0
ApplicationCloudfoundryUser Account And Authentication4.9.0
ApplicationCloudfoundryUser Account And Authentication4.8.3
ApplicationCloudfoundryUser Account And Authentication4.8.2
ApplicationCloudfoundryUser Account And Authentication4.8.1
ApplicationCloudfoundryUser Account And Authentication4.8.0
ApplicationCloudfoundryUser Account And Authentication4.7.6
ApplicationCloudfoundryUser Account And Authentication4.7.5
ApplicationCloudfoundryUser Account And Authentication4.7.4
ApplicationCloudfoundryUser Account And Authentication4.7.3
ApplicationCloudfoundryUser Account And Authentication4.7.2

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report