CWE-1390
Weak Authentication
Description
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Hierarchy (View 1000)
CVEs mapped to this weakness (96)
page 5 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41862 | Med | 0.34 | 5.3 | 0.01 | Dec 13, 2024 | Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0. | ||
| CVE-2022-45860 | Med | 0.34 | 5.3 | 0.00 | May 3, 2023 | A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying… | ||
| CVE-2024-32119 | Med | 0.31 | 4.8 | 0.00 | Jun 10, 2025 | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted… | ||
| CVE-2025-0605 | Med | 0.30 | 4.6 | 0.00 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements. | ||
| CVE-2026-49323 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM… | ||
| CVE-2026-49322 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN… | ||
| CVE-2024-8322 | Med | 0.28 | 4.3 | 0.01 | Sep 10, 2024 | Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality. | ||
| CVE-2024-5891 | Med | 0.27 | 4.2 | 0.00 | Jun 12, 2024 | A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not… | ||
| CVE-2024-29038 | Med | 0.21 | 4.3 | 0.00 | Jun 28, 2024 | tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7. | ||
| CVE-2023-41900 | Low | 0.16 | 3.5 | 0.01 | Sep 15, 2023 | Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already… | ||
| CVE-2025-29991 | Low | 0.14 | 2.2 | 0.00 | Apr 3, 2025 | Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification. | ||
| CVE-2026-80219 | 0.00 | — | 0.00 | Sep 8, 2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | |||
| CVE-2026-59554 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. | ||
| CVE-2026-50756 | Hig | 0.00 | 7.5 | 0.01 | Jul 21, 2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component | ||
| CVE-2026-57352 | Med | 0.00 | 4.8 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions. | ||
| CVE-2024-0822 | Hig | 0.00 | 7.5 | 0.01 | Jan 25, 2024 | An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command. |
- risk 0.34cvss 5.3epss 0.01
Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.
- risk 0.34cvss 5.3epss 0.00
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying…
- risk 0.31cvss 4.8epss 0.00
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted…
- risk 0.30cvss 4.6epss 0.00
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
- risk 0.28cvss 4.3epss 0.00
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM…
- risk 0.28cvss 4.3epss 0.00
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN…
- risk 0.28cvss 4.3epss 0.01
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
- risk 0.27cvss 4.2epss 0.00
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not…
- risk 0.21cvss 4.3epss 0.00
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.
- risk 0.16cvss 3.5epss 0.01
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already…
- risk 0.14cvss 2.2epss 0.00
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.
- CVE-2026-80219Sep 8, 2026risk 0.00cvss —epss 0.00
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
- risk 0.00cvss 7.5epss 0.01
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
- risk 0.00cvss 4.8epss 0.00
Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.
- risk 0.00cvss 7.5epss 0.01
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.