CWE-303: Incorrect Implementation of Authentication Algorithm
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
92 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-13390 — WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
- CVE-2024-4985 — An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sig
- CVE-2025-66489 — Cal.com Authentication Bypass via bad TOTP + password checks
- CVE-2025-12421 — Account Takeover via Code Exchange Endpoint
- CVE-2025-12419 — Account takeover on OAuth/OpenID-enabled servers
- CVE-2024-4332 — Improper Authentication in Tripwire Enterprise 9.1.0 APIs
- CVE-2025-14510 — ABB Ability OPTIMAX Authentication Bypass in Single-Sign On
- CVE-2024-10127 — Support for authentication bypass condition in M-Files LDAP authentication
- CVE-2025-4676 — Authentication bypass by brute forcing Authentication Headers
- CVE-2026-46389 — UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`
- CVE-2026-59309 — vCenter authentication-bypass vulnerability
- CVE-2025-57808 — ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
- CVE-2026-29515 — MiCode FileExplorer SwiFTP Server Authentication Bypass
- CVE-2025-43727 — Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-41053 — Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
- CVE-2025-43856 — immich allows account hijacking through oauth2
- CVE-2026-33190 — CoreDNS TSIG authentication bypass on encrypted DNS transports
- CVE-2026-10050 — Digest authentication lossy encoding
- CVE-2026-43640 — Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key
Recently published
- CVE-2026-78629 — Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling
- CVE-2026-9854 — A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their p
- CVE-2026-9853 — A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the a
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-66411 — DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut
- CVE-2026-11430 — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
- CVE-2026-10050 — Digest authentication lossy encoding
- CVE-2026-59309 — vCenter authentication-bypass vulnerability
- CVE-2026-66028 — Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email
- CVE-2026-57852 — Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
- CVE-2026-41053 — Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
- CVE-2026-41049 — Caching of Authentication allows Authentication Bypass between users in qSnapper
- CVE-2026-41048 — Caching of Authentication allows Authentication Bypass in qSnapper
- CVE-2026-46389 — UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`
- CVE-2026-8922 — Org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: security flaw in org.keycloak/keycloak-services
- CVE-2026-43640 — Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key
- CVE-2026-33190 — CoreDNS TSIG authentication bypass on encrypted DNS transports
- CVE-2026-27656 — Account Takeover via Substring Matching in OpenID Connect Authentication
- CVE-2026-32953 — Tillitis: TKey Client has an Error in Protocol Implementation
- CVE-2026-29515 — MiCode FileExplorer SwiFTP Server Authentication Bypass
More specific weaknesses
- CWE-304 — Missing Critical Step in Authentication