ClassIncomplete

CWE-1390Weak Authentication

Category: auth

Description

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Common consequences· 1

  • Integrity / Confidentiality / Availability / Access Control — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
    This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

References

  1. https://cwe.mitre.org/data/definitions/1390.html

(incoming)28

TypeTargetConfidenceTier
VulnerabilityCVE-2025-12870cve-2025-128700%live
VulnerabilityCVE-2025-12871cve-2025-128710%live
VulnerabilityCVE-2025-1293cve-2025-12930%live
VulnerabilityCVE-2025-1387cve-2025-13870%live
VulnerabilityCVE-2025-1727cve-2025-17270%live
VulnerabilityCVE-2025-23058cve-2025-230580%live
VulnerabilityCVE-2025-26343cve-2025-263430%live
VulnerabilityCVE-2025-27740cve-2025-277400%live
VulnerabilityCVE-2025-30411cve-2025-304110%live
VulnerabilityCVE-2025-30412cve-2025-304120%live
VulnerabilityCVE-2025-31676cve-2025-316760%live
VulnerabilityCVE-2025-39596cve-2025-395960%live
VulnerabilityCVE-2025-40552cve-2025-405520%live
VulnerabilityCVE-2025-40554cve-2025-405540%live
VulnerabilityCVE-2025-47479cve-2025-474790%live
VulnerabilityCVE-2025-47995cve-2025-479950%live
VulnerabilityCVE-2025-49201cve-2025-492010%live
VulnerabilityCVE-2025-5484cve-2025-54840%live
VulnerabilityCVE-2025-59249cve-2025-592490%live
VulnerabilityCVE-2025-63807cve-2025-638070%live
VulnerabilityCVE-2026-0204cve-2026-02040%live
VulnerabilityCVE-2026-27478cve-2026-274780%live
VulnerabilityCVE-2026-28710cve-2026-287100%live
VulnerabilityCVE-2026-4828cve-2026-48280%live
VulnerabilityCVE-2026-4924cve-2026-49240%live
VulnerabilityCVE-2026-6886cve-2026-68860%live
KEVEntryMicrosoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerabilitykev-cve-2021-386470%live
KEVEntryMicrosoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerabilitykev-cve-2021-386480%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Insufficiently Protected Credentials
CWE
Use of Single-factor Authentication
CWE
Missing Authentication for Critical Function
CWE
Use of Weak Credentials
CWE
Improper Access Control
CWE
Exposure of Sensitive Information to an Unauthorized Actor
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.