CWE-1390
Weak Authentication
Description
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Hierarchy (View 1000)
CVEs mapped to this weakness (89)
page 3 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-52541 | Hig | 0.53 | 8.2 | 0.00 | Feb 19, 2025 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||
| CVE-2025-26343 | Hig | 0.53 | 8.1 | 0.01 | Feb 12, 2025 | A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests. | ||
| CVE-2026-0204 | Hig | 0.52 | 8.0 | 0.00 | Apr 29, 2026 | A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | ||
| CVE-2026-10714 | Hig | 0.51 | — | 0.00 | Jul 14, 2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an… | ||
| CVE-2026-40417 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2026 | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-15595 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2026 | Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions. | ||
| CVE-2025-50173 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-49019 | Hig | 0.51 | 7.8 | 0.02 | Nov 12, 2024 | Active Directory Certificate Services Elevation of Privilege Vulnerability | ||
| CVE-2026-1693 | Hig | 0.49 | 7.5 | 0.00 | Feb 26, 2026 | The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to… | ||
| CVE-2025-57713 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2026 | A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later | ||
| CVE-2025-11084 | — | Hig | 0.49 | — | 0.00 | Nov 11, 2025 | A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period. | |
| CVE-2024-47397 | Hig | 0.49 | 7.5 | 0.00 | Dec 18, 2024 | Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string. | ||
| CVE-2024-35248 | Hig | 0.48 | 7.3 | 0.01 | Jun 11, 2024 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | ||
| CVE-2025-70994 | Hig | 0.47 | 7.3 | 0.00 | Apr 23, 2026 | Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is… | ||
| CVE-2024-50563 | Hig | 0.47 | 7.3 | 0.01 | Jan 16, 2025 | A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through… | ||
| CVE-2024-38239 | Hig | 0.47 | 7.2 | 0.02 | Sep 10, 2024 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2025-7326 | Hig | 0.46 | 7.0 | 0.01 | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon… | ||
| CVE-2025-24070 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-1293 | Hig | 0.46 | 8.2 | 0.00 | Feb 20, 2025 | Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0. | ||
| CVE-2025-30468 | Med | 0.42 | 6.5 | 0.00 | Sep 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication. |
- risk 0.53cvss 8.2epss 0.00
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- risk 0.53cvss 8.1epss 0.01
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.
- risk 0.52cvss 8.0epss 0.00
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
- risk 0.51cvss —epss 0.00
A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an…
- risk 0.51cvss 7.8epss 0.00
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
- risk 0.51cvss 7.8epss 0.00
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Active Directory Certificate Services Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.00
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to…
- risk 0.49cvss 7.5epss 0.01
A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later
- risk 0.49cvss —epss 0.00
A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period.
- risk 0.49cvss 7.5epss 0.00
Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string.
- risk 0.48cvss 7.3epss 0.01
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
- risk 0.47cvss 7.3epss 0.00
Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is…
- risk 0.47cvss 7.3epss 0.01
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through…
- risk 0.47cvss 7.2epss 0.02
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon…
- risk 0.46cvss 7.0epss 0.01
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- risk 0.46cvss 8.2epss 0.00
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.
- risk 0.42cvss 6.5epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication.