Cyber Resilience

CWE · MITRE source

CWE-603Use of Client-Side Authentication

Abstraction: Base · CVEs in our corpus: 22

A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

Client-side authentication is extremely weak and may be breached easily. Any attacker may read the source code and reverse-engineer the authentication mechanism to access parts of the application which would otherwise be protected.

Last updated: 22 August 2026 14:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-03
  • IA-2 Identification and Authentication (Organizational Users)
  • AC-3 Access Enforcement
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V10.4.10
  • V10.4.15
  • V10.4.16
  • V10.7.1

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-3218 9.89.80.73482022-09-19
CVE-2017-7909 7.79.80.02622017-05-06
CVE-2022-33139 7.59.80.01202022-06-21
CVE-2024-39375 7.49.80.00572024-06-27
CVE-2025-12868 7.39.80.00522025-11-10
CVE-2026-1363 7.39.80.00552026-01-23
CVE-2020-7591 6.88.80.01482020-10-15
CVE-2020-6988 6.47.50.04022020-03-16
CVE-2025-61940 6.28.30.00332025-12-02
CVE-2025-24517 6.07.50.00792025-03-31
CVE-2025-62650 6.08.30.00472025-10-17
CVE-2021-43355 5.97.30.00982022-01-21
CVE-2024-28627 5.87.50.00432024-04-23
CVE-2024-45785 5.87.50.00432024-10-25
CVE-2025-30042 5.57.80.00092026-03-02
CVE-2020-27266 5.26.50.00582021-01-19
CVE-2024-52327 5.16.50.00482025-01-23
CVE-2025-62649 4.65.80.00482025-10-17
CVE-2026-8830 3.74.30.00392026-05-19