CWE · MITRE source
CWE-302Authentication Bypass by Assumed-Immutable Data
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 7 mapping(s) from 2 framework(s): CAPEC 6 (partial) · ATT&CK 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
IA-8 | Identification and Authentication (Non-organizational Users) | IA | Proper authentication for non-organizational users counters bypasses relying on assumed-immutable data. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-43441 UPD | 9.8 | 9.8 | 0.6944 | 2024-12-24 |
CVE-2016-9482 UPD | 7.9 | 9.8 | 0.0466 | 2018-07-13 |
CVE-2025-29813 UPD | 7.7 | 10.0 | 0.0168 | 2025-05-08 |
CVE-2023-4669 UPD | 7.5 | 9.8 | 0.0097 | 2023-09-14 |
CVE-2023-4612 UPD | 7.5 | 9.8 | 0.0094 | 2023-11-09 |
CVE-2025-63210 UPD | 7.3 | 9.8 | 0.0055 | 2025-11-19 |
CVE-2024-56404 UPD | 7.0 | 9.9 | 0.0068 | 2025-01-24 |
CVE-2026-48781 | 6.8 | 9.9 | 0.0021 | 2026-06-17 |
CVE-2022-22729 UPD | 6.7 | 8.8 | 0.0095 | 2022-03-11 |
CVE-2024-4024 UPD | 6.7 | 7.3 | 0.1490 | 2024-04-25 |
CVE-2024-12838 UPD | 6.7 | 8.8 | 0.0074 | 2024-12-31 |
CVE-2026-47303 UPD | 6.7 | 8.8 | 0.0074 | 2026-07-14 |
CVE-2025-47158 UPD | 6.4 | 9.0 | 0.0067 | 2025-07-18 |
CVE-2026-40285 | 6.4 | 8.8 | 0.0027 | 2026-04-17 |
CVE-2026-50528 UPD | 6.3 | 8.2 | 0.0055 | 2026-07-14 |
CVE-2026-39429 UPD | 6.2 | 8.2 | 0.0044 | 2026-04-08 |
CVE-2020-15074 UPD | 6.1 | 7.5 | 0.0104 | 2020-07-14 |
CVE-2025-24876 UPD | 6.1 | 8.1 | 0.0049 | 2025-02-11 |
CVE-2025-8855 UPD | 6.1 | 8.1 | 0.0037 | 2025-11-14 |
CVE-2026-13267 | 6.0 | 8.1 | 0.0025 | 2026-08-12 |
CVE-2022-3875 UPD | 5.9 | 7.3 | 0.0097 | 2022-12-19 |
CVE-2024-3741 UPD | 5.9 | 7.5 | 0.0049 | 2024-04-18 |
CVE-2024-22179 UPD | 5.8 | 7.5 | 0.0039 | 2024-04-18 |
CVE-2024-49056 UPD | 5.8 | 7.3 | 0.0102 | 2024-11-12 |
CVE-2024-47086 UPD | 5.1 | 6.5 | 0.0047 | 2024-09-19 |