CWE-1390

Weak Authentication

Parent: CWE-287 - Improper Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

81 vulnerabilities with CWE-1390
CVE-2025-11084 HIGH
DataMosaix Private Cloud - Auth Bypass
CVE-2025-59249 HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 8.8
CVE-2025-49201 HIGH
Fortinet FortiPAM 1.0.0-1.4.2 and FortiSwitchManager 7.2.0-7.2.4 - Weak Authentication
CVSS 8.1
CVE-2025-30468 MEDIUM
iPadOS < 26.0 - Unauthenticated Private Browsing Tab Access
CVSS 6.5
CVE-2025-50173 HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2025-47995 MEDIUM
Azure Machine Learning - Privilege Escalation
CVSS 6.5
CVE-2025-1727 HIGH
End-of-Train/Head-of-Train Protocol - Unauthenticated Brake Command Injection via RF Spoofing
CVSS 8.1
CVE-2025-7326 HIGH
ASP.NET Core - Privilege Escalation
CVSS 7.0
CVE-2025-47479 MEDIUM
AresIT WP Compress <6.30.30 - Auth Bypass
CVSS 5.3
CVE-2025-5484 HIGH
SinoTrack IOT PC Platform - Weak Authentication via Default Credentials
CVSS 8.3
CVE-2025-0605 MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Auth Bypass
CVSS 4.6
CVE-2025-32885 MEDIUM
goTenna v1 <5.5.3-0.25.5 - Code Injection
CVSS 6.5
CVE-2025-39596 CRITICAL
Quentn WP <1.2.8 - Privilege Escalation
CVSS 9.8
CVE-2025-27740 HIGH
Windows Active Directory Certificate Services - Privilege Escalation
CVSS 8.8
CVE-2025-26635 MEDIUM
Windows 10/11, Server 2019/2022 - Weak Authentication in Windows Hello
CVSS 6.5
CVE-2025-29991 LOW
Yubico YubiKey 5.4.1-5.7.3 - Info Disclosure
CVSS 2.2
CVE-2025-31676 HIGH
Drupal Email TFA <2.0.3 - Auth Bypass
CVSS 8.8
CVE-2025-29994 HIGH
CAP back office application < 2.0.4 - Unauthenticated Weak Authentication via API Endpoint
CVE-2025-24070 HIGH
ASP.NET Core & Visual Studio - Privilege Escalation
CVSS 7.0
CVE-2025-1293 HIGH
Hermes < 0.5.0 - Authentication Bypass via Improper AWS ALB JWT Validation
CVSS 8.2
CVE-2025-1387 CRITICAL
Orca HCM < 11.0 - Unauthenticated Weak Authentication
CVSS 9.8
CVE-2025-26343 HIGH
Q-Free MaxTime <= 2.11.0 - Auth Bypass
CVSS 8.1
CVE-2025-23058 HIGH
ClearPass Policy Manager - Privilege Escalation
CVSS 8.8
CVE-2025-21552 MEDIUM
Oracle JD Edwards <9.2.9.2 - Unauthorized Access
CVSS 6.5
CVE-2024-32119 MEDIUM
Fortinet FortiClientEMS <7.2.4 - Auth Bypass
CVSS 4.8
Details
Vulnerabilities 81