CWE-1390

Weak Authentication

Parent: CWE-287 - Improper Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

86 vulnerabilities with CWE-1390
CVE-2026-59554 HIGH
WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-50756 HIGH
next-ai-draw-io 0.4.13 - Unauthenticated Sensitive Information Disclosure via x-ai-provider Header
CVSS 7.5
CVE-2026-55040 CRITICAL
Microsoft SharePoint Server Security Feature Bypass Vulnerability
CVSS 9.1
CVE-2026-10714 HIGH
Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Validation Bypass
CVE-2026-57352 MEDIUM
WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerability
CVSS 4.8
CVE-2026-0274 CRITICAL
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
CVSS 9.1
CVE-2026-6274 CRITICAL
Authentication Bypass in DTS Electronics' Redline WR3200
CVSS 9.8
CVE-2026-44237 HIGH
FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module
CVSS 8.1
CVE-2026-49323 MEDIUM
Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVSS 4.3
CVE-2026-49322 MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
CVE-2026-40417 HIGH
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-0204 HIGH
SonicWall SonicOS <=6.5.5.1-6n - Auth Bypass
CVSS 8.0
CVE-2026-6886 CRITICAL
BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
CVSS 9.8
CVE-2026-4924 HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-4828 HIGH
Devolutions Server <=2026.1.11 - Auth Bypass
CVSS 8.2
CVE-2026-32497 MEDIUM
WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability
CVSS 5.3
CVE-2026-27478 CRITICAL
Unity Catalog <=0.4.0 - Auth Bypass
CVSS 9.1
CVE-2026-28710 CRITICAL
Acronis Cyber Protect 17 - Info Disclosure
CVSS 9.8
CVE-2026-1693 HIGH
PcVue 12.0.0-16.3.3 - Credential Theft via Obsolete OAuth ROPC Flow
CVSS 7.5
CVE-2025-70994 HIGH
Yadea T5 Electric Bicycles 2024 - Auth Bypass
CVSS 7.3
CVE-2025-62844 MEDIUM
QNAP QuRouter < 2.6.2.007 - Weak Authentication Information Disclosure
CVSS 5.5
CVE-2025-15595 HIGH
Inno Setup <=6.2.1 - Privilege Escalation
CVSS 7.8
CVE-2025-30412 CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-30411 CRITICAL
Acronis Cyber Protect - Info Disclosure
CVSS 10.0
CVE-2025-57713 HIGH
File Station 5 <5.5.6.5166 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 86