CWE-620: Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Overview
This could be used by an attacker to change passwords for another user, thus gaining the privileges associated with that user.
Real-world CVEs
80 recorded CVEs are caused by CWE-620 (Unverified Password Change). The highest-severity and most recent are shown first. 13 new CWE-620 CVEs have been recorded so far in 2026 (36 in 2025).