A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.
Volume of CVEs assigned to CWE-603 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3218CRITICAL Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code exec | Sep 19, 2022 | 9.8 | 81 | NO | YES |
CVE-2025-12868CRITICAL New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain adminis | Nov 10, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-1363CRITICAL IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by mani | Jan 23, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-42098HIGH Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect | May 19, 2026 | 8.7 | 31 | NO | NO |
CVE-2025-62650CRITICAL The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen. | Oct 17, 2025 | 9.9 | 31 | NO | NO |
CVE-2022-33139CRITICAL A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default conf | Jun 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-7909CRITICAL A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client aut | May 6, 2017 | 9.8 | 31 | NO | NO |
CVE-2025-64119CRITICAL A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9. | Jan 2, 2026 | 9.3 | 29 | NO | NO |
CVE-2021-43355CRITICAL Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server s | Jan 21, 2022 | 9.8 | 29 | NO | NO |
CVE-2026-40551HIGH mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by mani | Apr 28, 2026 | 8.4 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.