CWE-303: Incorrect Implementation of Authentication Algorithm

What is CWE-303?

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK7 — A07:2025 — Authentication Failures
RELATED CVES (365 DAYS)30
ABSTRACTIONBase

Vulnerabilities mapped to CWE-303

30 vulnerabilities500% increase year over year

Vulnerabilities in CISA KEV for CWE-303

0 vulnerabilities

Official definition

ByMitre CWE

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

This incorrect implementation may allow authentication to be bypassed.

Characteristics

Modes of introduction

  • Implementation: REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Common consequences

ImpactScopeExplanation
Bypass Protection MechanismAccess Control—

Representative vulnerabilities

Below are representative vulnerabilities related to this CWE, prioritized by severity.

Sources (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan