CWE-1390Class1 in KEV

Weak Authentication

Incomplete in the CWE catalog · 80 CVEs mapped

80
CVEs mapped
1
In KEV
7.6
Median CVSS
What it is

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Recent examples
9.8cvss
CVE-2026-73819

CVE-2026-73819 - CRITICAL Severity Vulnerability

The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.

CRITICALno explanation yet
1%
epss
none
CVE-2026-44476

CVE-2026-44476 - UNKNOWN Severity Vulnerability

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.

no explanation yet
0%
epss
8.1cvss
CVE-2026-65098

CVE-2026-65098 - HIGH Severity Vulnerability

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-1390
Abstraction
Class
Structure
Simple
Status
Incomplete
References (1)