CWE-1390: Weak Authentication

What is CWE-1390?

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK7 — A07:2025 — Authentication Failures
RELATED CVES (365 DAYS)28
ABSTRACTIONClass

Vulnerabilities mapped to CWE-1390

28 vulnerabilities154.5% increase year over year

Vulnerabilities in CISA KEV for CWE-1390

1 vulnerabilities

Official definition

ByMitre CWE

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Attackers may be able to bypass weak authentication faster and/or with less effort than expected.

Characteristics

Modes of introduction

  • Architecture and Design
  • Implementation

Common consequences

ImpactScopeExplanation
Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or CommandsIntegrity, Confidentiality, Availability, Access ControlThis weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Representative vulnerabilities

Sources (3)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan