CWE-1390

Weak Authentication

Parent: CWE-287 - Improper Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

75 vulnerabilities with CWE-1390
CVE-2026-0204 HIGH
SonicWall SonicOS <=6.5.5.1-6n - Auth Bypass
CVSS 8.0
CVE-2026-6886 CRITICAL
BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
CVSS 9.8
CVE-2026-4924 HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-4828 HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-32497 MEDIUM
WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability
CVSS 5.3
CVE-2026-27478 CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-28710 CRITICAL
Acronis Cyber Protect 17 - Info Disclosure
CVSS 9.8
CVE-2026-1693 HIGH
PcVue 12.0.0-16.3.3 - Auth Bypass
CVSS 7.5
CVE-2025-70994 HIGH
Yadea T5 Electric Bicycles 2024 - Auth Bypass
CVSS 7.3
CVE-2025-62844 MEDIUM
QuRouter
CVSS 5.5
CVE-2025-15595 HIGH
Inno Setup <=6.2.1 - Privilege Escalation
CVSS 7.8
CVE-2025-30412 CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-30411 CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-57713 HIGH
File Station 5 <5.5.6.5166 - Info Disclosure
CVSS 7.5
CVE-2025-40554 CRITICAL
Solarwinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CVE-2025-40552 CRITICAL
Solarwinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CVE-2025-63807 CRITICAL
University-BBS <9e06bab430bfc729f27b4284ba7570db3b11ce84 - Auth Bypass
CVSS 9.8
CVE-2025-12871 CRITICAL
a+HRD - Privilege Escalation
CVSS 9.8
CVE-2025-12870 CRITICAL
a+HRD - Privilege Escalation
CVSS 9.8
CVE-2025-11084 HIGH
DataMosaix Private Cloud - Auth Bypass
CVE-2025-59249 HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 8.8
CVE-2025-49201 HIGH
Fortinet FortiPAM <1.5.0 - RCE
CVSS 8.1
CVE-2025-30468 MEDIUM
iOS <26 - Info Disclosure
CVSS 6.5
CVE-2025-50173 HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2025-47995 MEDIUM
Azure Machine Learning - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 75