The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Volume of CVEs assigned to CWE-1390 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40554CRITICAL SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Hel | Jan 28, 2026 | 9.8 | 79 | NO | YES |
CVE-2025-40552CRITICAL SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that | Jan 28, 2026 | 9.8 | 74 | NO | YES |
CVE-2026-55040CRITICAL Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 9.1 | 44 | NO | NO |
CVE-2026-6274CRITICAL Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Access | Jun 5, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-0274CRITICAL An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify | Jun 10, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-10714HIGH A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stem | Jul 14, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-0204HIGH A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | Apr 29, 2026 | 8.0 | 35 | NO | NO |
CVE-2025-30412CRITICAL Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni | Feb 20, 2026 | 10.0 | 35 | NO | NO |
CVE-2025-30411CRITICAL Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni | Feb 20, 2026 | 10.0 | 35 | NO | NO |
CVE-2025-63807CRITICAL An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism c | Nov 20, 2025 | 9.8 | 34 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.