CWE-1390: Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
84 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-40552 — SolarWinds Web Help Desk Authentication Bypass Vulnerability
- CVE-2025-40554 — SolarWinds Web Help Desk Authentication Bypass Vulnerability
- CVE-2025-30412 — Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
- CVE-2025-39596 — WordPress Quentn WP <= 1.2.8 - Privilege Escalation Vulnerability
- CVE-2025-1387 — Learning Digital Orca HCM - Improper Authentication
- CVE-2025-12871 — aEnrich|a+HRD - Authentication Abuse
- CVE-2025-12870 — aEnrich|eHRD - Authentication Abuse
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2024-29837 — Poor session management in Evolution Controller allows administrator functionality for unauthenticated connections
- CVE-2025-5484 — SinoTrack GPS Receiver Weak Authentication
- CVE-2026-4924 — Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all
- CVE-2026-4828 — Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att
- CVE-2025-29994 — Improper Authentication Vulnerability in CAP back office application
- CVE-2025-1293 — HashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication Bypass
- CVE-2024-52541 — Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access cou
- CVE-2026-6274 — Authentication Bypass in DTS Electronics' Redline WR3200
- CVE-2026-28710 — Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A
- CVE-2025-26343 — A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.1
- CVE-2025-1727 — End-of-Train and Head-of-Train Remote Linking Protocol Weak Authentication
- CVE-2024-48886 — A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0
Recently published
- CVE-2026-80219 — Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret enables oauth token theft
- CVE-2026-73819 — Ebyte NA111-M Weak Authentication
- CVE-2026-44476 — Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secret
- CVE-2026-65098 — NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w
- CVE-2026-68067 — Mira Hormone Monitor, Mira Android App Weak Authentication
- CVE-2026-59554 — WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
- CVE-2026-10714 — Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Validation Bypass
- CVE-2026-57352 — WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerability
- CVE-2026-0274 — Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
- CVE-2026-6274 — Authentication Bypass in DTS Electronics' Redline WR3200
- CVE-2026-44237 — FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module
- CVE-2026-49323 — Indian Scout Bobber 2025 WCM-to-ECM weak authentication
- CVE-2026-49322 — Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recovery of user PIN from observed exchange
- CVE-2026-0204 — A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access
- CVE-2026-6886 — BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
- CVE-2026-4924 — Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all
- CVE-2026-4828 — Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att
- CVE-2026-32497 — WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability
- CVE-2025-62844 — QuRouter
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
More specific weaknesses
- CWE-1391 — Use of Weak Credentials
- CWE-262 — Not Using Password Aging
- CWE-263 — Password Aging with Long Expiration
- CWE-289 — Authentication Bypass by Alternate Name
- CWE-290 — Authentication Bypass by Spoofing
- CWE-294 — Authentication Bypass by Capture-replay
- CWE-301 — Reflection Attack in an Authentication Protocol
- CWE-302 — Authentication Bypass by Assumed-Immutable Data
- CWE-303 — Incorrect Implementation of Authentication Algorithm
- CWE-305 — Authentication Bypass by Primary Weakness
- CWE-307 — Improper Restriction of Excessive Authentication Attempts
- CWE-308 — Use of Single-factor Authentication
- CWE-309 — Use of Password System for Primary Authentication
- CWE-522 — Insufficiently Protected Credentials
- CWE-603 — Use of Client-Side Authentication
- CWE-620 — Unverified Password Change
- CWE-640 — Weak Password Recovery Mechanism for Forgotten Password
- CWE-836 — Use of Password Hash Instead of Password for Authentication