CWE-1390: Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Overview
Attackers may be able to bypass weak authentication faster and/or with less effort than expected.
Real-world CVEs
74 recorded CVEs are caused by CWE-1390 (Weak Authentication). The highest-severity and most recent are shown first. 16 new CWE-1390 CVEs have been recorded so far in 2026 (35 in 2025).