Cyber Resilience

CWE · MITRE source

CWE-302Authentication Bypass by Assumed-Immutable Data

Abstraction: Base · CVEs in our corpus: 42

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 7 mapping(s) from 2 framework(s): CAPEC 6 (partial) · ATT&CK 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • IA-8 Identification and Authentication (Non-organizational Users)
  • PR.AA-03
  • PR.AA-04
  • AC-3 Access Enforcement
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V7.2.4

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
IA-8Identification and Authentication (Non-organizational Users)IAProper authentication for non-organizational users counters bypasses relying on assumed-immutable data.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-43441 9.89.80.69442024-12-24
CVE-2016-9482 7.99.80.04662018-07-13
CVE-2025-29813 7.710.00.01682025-05-08
CVE-2023-4669 7.59.80.00972023-09-14
CVE-2023-4612 7.59.80.00942023-11-09
CVE-2025-63210 7.39.80.00552025-11-19
CVE-2024-56404 7.09.90.00682025-01-24
CVE-2026-487816.89.90.00212026-06-17
CVE-2022-22729 6.78.80.00952022-03-11
CVE-2024-4024 6.77.30.14902024-04-25
CVE-2024-12838 6.78.80.00742024-12-31
CVE-2026-47303 6.78.80.00742026-07-14
CVE-2025-47158 6.49.00.00672025-07-18
CVE-2026-402856.48.80.00272026-04-17
CVE-2026-50528 6.38.20.00552026-07-14
CVE-2026-39429 6.28.20.00442026-04-08
CVE-2020-15074 6.17.50.01042020-07-14
CVE-2025-24876 6.18.10.00492025-02-11
CVE-2025-8855 6.18.10.00372025-11-14
CVE-2026-132676.08.10.00252026-08-12
CVE-2022-3875 5.97.30.00972022-12-19
CVE-2024-3741 5.97.50.00492024-04-18
CVE-2024-22179 5.87.50.00392024-04-18
CVE-2024-49056 5.87.30.01022024-11-12
CVE-2024-47086 5.16.50.00472024-09-19