Cyber Posture

CWE · MITRE source

CWE-1390Weak Authentication

Abstraction: Class · CVEs in our corpus: 75

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Attackers may be able to bypass weak authentication faster and/or with less effort than expected.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (5)AI

Showing the 4 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
IA-1Policy and ProceduresIAThe IA policy requires strong authentication methods, reducing use of weak authentication.
IA-10Adaptive AuthenticationIAEnforces dynamic, context-aware authentication that mitigates weak static authentication by increasing requirements based on risk or conditions.
IA-2Identification and Authentication (Organizational Users)IAEnforces authentication for users, reducing the viability of weak authentication mechanisms.
AC-9Previous Logon NotificationACHelps detect exploitation of weak authentication mechanisms by notifying of previous unauthorized logons.
Show 1 more broadly-applicable controls
IA-7Cryptographic Module AuthenticationIARequires authentication mechanisms to meet applicable standards and guidelines, preventing weak authentication.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-405522.59.80.08552026-01-28
CVE-2025-405542.39.80.06292026-01-28
CVE-2022-434002.09.80.01192022-10-21
CVE-2023-493402.09.80.00262024-03-09
CVE-2024-132392.09.80.00432025-01-09
CVE-2025-13872.09.80.00612025-02-17
CVE-2024-540922.09.80.00482025-04-08
CVE-2025-395962.09.80.00282025-04-17
CVE-2025-128702.09.80.00142025-11-12
CVE-2025-128712.09.80.00232025-11-12
CVE-2025-638072.09.80.00112025-11-20
CVE-2023-538942.09.80.00502025-12-16
CVE-2025-304112.010.00.00052026-02-20
CVE-2025-304122.010.00.00052026-02-20
CVE-2026-287102.09.80.00102026-03-06
CVE-2026-68862.09.80.00192026-04-23
CVE-2024-344511.99.10.00692024-06-16
CVE-2024-381821.99.00.02012024-07-31
CVE-2025-277401.98.80.01712025-04-08
CVE-2024-298371.88.80.00202024-04-15
CVE-2024-367871.88.80.00022024-06-07
CVE-2024-398481.89.10.00072024-06-29
CVE-2024-453671.89.10.00132024-10-03
CVE-2024-490191.87.80.04832024-11-12
CVE-2024-488861.89.00.00562025-01-14