CWE · MITRE source
CWE-1390Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Attackers may be able to bypass weak authentication faster and/or with less effort than expected.
Last updated: 21 August 2026 14:15 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 6 mapping(s) from 6 framework(s): STIG rhel 7 1 (mostly) · STIG rhel 8 1 (mostly) · STIG ubuntu 22 04 1 (mostly) · STIG windows 10 1 (mostly) · STIG windows 11 1 (mostly) · STIG oracle linux 8 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 9 hardening rules · 7 OS baselines
V7.6.1V6.3.6V6.4.2V6.4.4
NIST 800-53 r5 controls that address this weakness (5)AI-assisted
Showing the 4 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
IA-1 | Policy and Procedures | IA | The IA policy requires strong authentication methods, reducing use of weak authentication. |
IA-10 | Adaptive Authentication | IA | Enforces dynamic, context-aware authentication that mitigates weak static authentication by increasing requirements based on risk or conditions. |
IA-2 | Identification and Authentication (Organizational Users) | IA | Enforces authentication for users, reducing the viability of weak authentication mechanisms. |
AC-9 | Previous Logon Notification | AC | Helps detect exploitation of weak authentication mechanisms by notifying of previous unauthorized logons. |
Show 1 more broadly-applicable controls
IA-7 | Cryptographic Module Authentication | IA | Requires authentication mechanisms to meet applicable standards and guidelines, preventing weak authentication. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2025-40554 | 9.5 | 9.8 | 0.5731 | 2026-01-28 |
CVE-2026-55040 KEV UPD | 9.5 | 9.1 | 0.0549 | 2026-07-14 |
CVE-2025-40552 UPD | 9.3 | 9.8 | 0.4973 | 2026-01-28 |
CVE-2022-43400 UPD | 7.5 | 9.8 | 0.0094 | 2022-10-21 |
CVE-2023-49340 UPD | 7.5 | 9.8 | 0.0086 | 2024-03-09 |
CVE-2025-30411 UPD | 7.5 | 10.0 | 0.0069 | 2026-02-20 |
CVE-2025-30412 UPD | 7.5 | 10.0 | 0.0062 | 2026-02-20 |
CVE-2025-1387 UPD | 7.4 | 9.8 | 0.0057 | 2025-02-17 |
CVE-2024-54092 UPD | 7.4 | 9.8 | 0.0074 | 2025-04-08 |
CVE-2025-12870 | 7.4 | 9.8 | 0.0062 | 2025-11-12 |
CVE-2025-12871 | 7.4 | 9.8 | 0.0058 | 2025-11-12 |
CVE-2023-53894 UPD | 7.4 | 9.8 | 0.0063 | 2025-12-16 |
CVE-2024-13239 UPD | 7.3 | 9.8 | 0.0056 | 2025-01-09 |
CVE-2025-39596 UPD | 7.3 | 9.8 | 0.0056 | 2025-04-17 |
CVE-2025-63807 UPD | 7.3 | 9.8 | 0.0049 | 2025-11-20 |
CVE-2026-28710 | 7.3 | 9.8 | 0.0041 | 2026-03-06 |
CVE-2026-6886 UPD | 7.3 | 9.8 | 0.0045 | 2026-04-23 |
CVE-2026-6274 UPD | 7.3 | 9.8 | 0.0046 | 2026-06-05 |
CVE-2026-68067 | 7.2 | 9.8 | 0.0028 | 2026-08-11 |
CVE-2025-27740 UPD | 7.1 | 8.8 | 0.0327 | 2025-04-08 |
CVE-2024-34451 UPD | 7.0 | 9.1 | 0.0077 | 2024-06-16 |
CVE-2024-45367 UPD | 6.9 | 9.1 | 0.0051 | 2024-10-03 |
CVE-2024-39848 UPD | 6.8 | 9.1 | 0.0044 | 2024-06-29 |
CVE-2025-23058 UPD | 6.7 | 8.8 | 0.0071 | 2025-02-04 |
CVE-2025-59249 UPD | 6.7 | 8.8 | 0.0077 | 2025-10-14 |