Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-1390

MITRE ↗

CWE-1390

11
CRITICAL
12
HIGH
6
MEDIUM
31 CVEs
10.0
CVE-2025-30411

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis

10.0
CVE-2025-30412

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis

9.8
CVE-2025-40552

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would

9.8
CVE-2025-40554

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could

9.8
CVE-2026-28710

Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A

9.8
CVE-2026-6886

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability,

9.8
CVE-2026-6274

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron

9.8
CVE-2026-68067

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active

9.1
CVE-2026-27478

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu

9.1
CVE-2026-0274

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X

9.1
CVE-2026-55040 KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n

8.2
CVE-2026-4828

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att

8.2
CVE-2026-4924

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all

8.1
CVE-2026-44237

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently

8.1
CVE-2026-65098

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w

8.0
CVE-2026-0204

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access

7.8
CVE-2025-15595

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

7.8
CVE-2026-40417

Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-57713

A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit th

7.5
CVE-2026-1693

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVu

7.5
CVE-2026-50756

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro

7.5
CVE-2026-59554

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

7.3
CVE-2025-70994

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent

5.5
CVE-2025-62844

A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c

5.5
CVE-2026-59135

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

5.3
CVE-2026-32497

Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is

4.8
CVE-2026-57352

Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 vers

4.3
CVE-2026-49322

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year al

4.3
CVE-2026-49323

Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc

CVE-2026-10714

A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature valid

CVE-2026-44476

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically register

Frequently Asked Questions

What is CWE-1390?

CWE-1390 (CWE-1390) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-1390?

There are 31 CVE records associated with CWE-1390 in our database. Of these, 11 are critical severity, 12 are high severity, and 6 are medium severity.

How can I protect against CWE-1390 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1390 using AI-powered security agents.

Detect CWE-1390 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-1390 vulnerabilities across your infrastructure.

Get Started