A07 - Authentication Failures 12
- JWT Algorithm Confusion Leads to Privilege Escalation | Halftone Studio
- Authentication Bypass via Forged Remember-Me Cookie | Skein
- Weak Credentials – Member Account Compromise | Pinegrass Library Co-op
- Default Credentials Authentication Weakness | Lake Forks Permits
- Weak Password Reset – Brute Force of 4-Digit Reset Token Leading to Account Takeover | Heartwood Outfitters
- Weak Credentials – Authentication Compromise via Password Brute Force | Halftrack Model Railroad Club
- JWT Secret Cracking & Privilege Escalation via Forged Tokens | Tally
- JWT alg:none Authentication Bypass to Admin Access | EverGreen
- Predictable Time-Based Auth Token Leading to Authentication Bypass | Sokudo
- Weak Session Token Design – Predictable MD5-Based Session Hijacking | CopyPasta
- OTP Bypass & Brute Force – Admin Account Takeover via Password Reset | Cheesy Does it
- Broken Authentication – Predictable Timestamp Token Leads to Admin Account Takeover | Sokudo