CWE-1390

Weak Authentication

Parent: CWE-287 - Improper Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

81 vulnerabilities with CWE-1390
CVE-2026-0274 HIGH
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
CVE-2026-6274 CRITICAL
Authentication Bypass in DTS Electronics' Redline WR3200
CVSS 9.8
CVE-2026-44237 HIGH
FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module
CVSS 8.1
CVE-2026-49323 MEDIUM
Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVSS 4.3
CVE-2026-49322 MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
CVE-2026-40417 HIGH
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-0204 HIGH
SonicWall SonicOS <=6.5.5.1-6n - Auth Bypass
CVSS 8.0
CVE-2026-6886 CRITICAL
BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
CVSS 9.8
CVE-2026-4924 HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-4828 HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-32497 MEDIUM
WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability
CVSS 5.3
CVE-2026-27478 CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-28710 CRITICAL
Acronis Cyber Protect 17 - Info Disclosure
CVSS 9.8
CVE-2026-1693 HIGH
PcVue 12.0.0-16.3.3 - Credential Theft via Obsolete OAuth ROPC Flow
CVSS 7.5
CVE-2025-70994 HIGH
Yadea T5 Electric Bicycles 2024 - Auth Bypass
CVSS 7.3
CVE-2025-62844 MEDIUM
QNAP QuRouter < 2.6.2.007 - Weak Authentication Information Disclosure
CVSS 5.5
CVE-2025-15595 HIGH
Inno Setup <=6.2.1 - Privilege Escalation
CVSS 7.8
CVE-2025-30412 CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-30411 CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-57713 HIGH
File Station 5 <5.5.6.5166 - Info Disclosure
CVSS 7.5
CVE-2025-40554 CRITICAL
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CVE-2025-40552 CRITICAL
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
CVSS 9.8
CVE-2025-63807 CRITICAL
University-BBS <9e06bab430bfc729f27b4284ba7570db3b11ce84 - Auth Bypass
CVSS 9.8
CVE-2025-12871 CRITICAL
aenrich a+HRD < 7.5 - Unauthenticated Authentication Abuse via Crafted Administrator Token
CVSS 9.8
CVE-2025-12870 CRITICAL
a+HRD < 7.5 - Unauthenticated Authentication Abuse via Crafted Packets
CVSS 9.8
Details
Vulnerabilities 81