VYPR

CWE-1390

Weak Authentication

ClassIncomplete

Description

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Hierarchy (View 1000)

CVEs mapped to this weakness (96)

page 3 of 5
  • CVE-2026-4924HigApr 1, 2026
    risk 0.53cvss 8.2epss 0.00

    Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially…

  • CVE-2026-4828HigApr 1, 2026
    risk 0.53cvss 8.2epss 0.00

    Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.

  • CVE-2025-49201HigOct 14, 2025
    risk 0.53cvss 8.1epss 0.01

    A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute…

  • CVE-2025-1727HigJul 10, 2025
    risk 0.53cvss 8.1epss 0.01

    The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and issue brake control commands to the EoT …

  • CVE-2025-29994HigMar 13, 2025
    risk 0.53cvss —epss 0.00

    This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. An unauthenticated remote attacker with a valid login ID could exploit this vulnerability by manipulating API input parameters through API request URL/payload…

  • CVE-2024-52541HigFeb 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2025-26343HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.01

    A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.

  • CVE-2026-0204HigApr 29, 2026
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

  • CVE-2026-10714HigJul 14, 2026
    risk 0.51cvss —epss 0.00

    A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an…

  • CVE-2026-40417HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

  • CVE-2025-15595HigMar 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

  • CVE-2025-50173HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2024-49019HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.02

    Active Directory Certificate Services Elevation of Privilege Vulnerability

  • CVE-2026-1693HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to…

  • CVE-2025-57713HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.01

    A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

  • CVE-2025-11084HigNov 11, 2025
    risk 0.49cvss —epss 0.00

    A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period.

  • CVE-2024-47397HigDec 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string.

  • CVE-2024-35248HigJun 11, 2024
    risk 0.48cvss 7.3epss 0.01

    Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

  • CVE-2025-70994HigApr 23, 2026
    risk 0.47cvss 7.3epss 0.00

    Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is…

  • CVE-2024-50563HigJan 16, 2025
    risk 0.47cvss 7.3epss 0.01

    A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through…