CWE-303: Incorrect Implementation of Authentication Algorithm
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Overview
This incorrect implementation may allow authentication to be bypassed.
Real-world CVEs
76 recorded CVEs are caused by CWE-303 (Incorrect Implementation of Authentication Algorithm), including 1 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 13 new CWE-303 CVEs have been recorded so far in 2026 (18 in 2025).