Known Vulnerabilities for Authenticator by Google
Listed below are 1 of the newest known vulnerabilities associated with "Authenticator" by "Google".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62236 json | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret f... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-55689 json | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT... | Not Provided | 2026-07-09 | 2026-07-10 |
| CVE-2026-48087 json | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version ... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-46389 json | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's ... | Not Provided | 2026-06-05 | 2026-06-05 |
| CVE-2026-44460 json | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-18677 json | In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-14204 json | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-10665 json | In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbound tr... | Not Provided | 2026-07-12 | 2026-07-14 |
| CVE-2026-7163 json | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multiclu... | Not Provided | 2026-04-30 | 2026-08-20 |
| CVE-2025-15039 json | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required aut... | Not Provided | 2026-08-06 | 2026-08-06 |