A07:2025 Authentication Failures
Identity verification can be bypassed, brute-forced, or hijacked. Credential stuffing, weak password reset flows, session-management mistakes.
Member CWEs (36)
- CWE-258 Empty Password in Configuration File
- CWE-259 Use of Hard-coded Password
- CWE-287 Improper Authentication
- CWE-288 Authentication Bypass Using an Alternate Path or Channel
- CWE-289 Authentication Bypass by Alternate Name
- CWE-290 Authentication Bypass by Spoofing
- CWE-291 Reliance on IP Address for Authentication
- CWE-293 Using Referer Field for Authentication
- CWE-294 Authentication Bypass by Capture-replay
- CWE-295 Improper Certificate Validation
- CWE-297 Improper Validation of Certificate with Host Mismatch
- CWE-298 Improper Validation of Certificate Expiration
- CWE-299 Improper Check for Certificate Revocation
- CWE-300 Channel Accessible by Non-Endpoint
- CWE-302 Authentication Bypass by Assumed-Immutable Data
- CWE-303 Incorrect Implementation of Authentication Algorithm
- CWE-304 Missing Critical Step in Authentication
- CWE-305 Authentication Bypass by Primary Weakness
- CWE-306 Missing Authentication for Critical Function
- CWE-307 Improper Restriction of Excessive Authentication Attempts
- CWE-308 Use of Single-factor Authentication
- CWE-309 Use of Password System for Primary Authentication
- CWE-346 Origin Validation Error
- CWE-350 Reliance on Reverse DNS Resolution for a Security-Critical Action
- CWE-384 Session Fixation
- CWE-521 Weak Password Requirements
- CWE-613 Insufficient Session Expiration
- CWE-620 Unverified Password Change
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password
- CWE-798 Use of Hard-coded Credentials
- CWE-940 Improper Verification of Source of a Communication Channel
- CWE-941 Incorrectly Specified Destination in a Communication Channel
- CWE-1390 Weak Authentication
- CWE-1391 Use of Weak Credentials
- CWE-1392 Use of Default Credentials
- CWE-1393 Use of Default Password
Mapped NIST 800-53 r5 controls (4)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 15,825)
- CVE-2026-77644
- CVE-2026-77264
- CVE-2026-76633
- CVE-2026-76403
- CVE-2026-76392
- CVE-2026-76362
- CVE-2026-76356
- CVE-2026-76355
- CVE-2026-76338
- CVE-2026-76242
- CVE-2026-76214
- CVE-2026-76213
- CVE-2026-76207
- CVE-2026-76157
- CVE-2026-76155
- CVE-2026-76137
- CVE-2026-76131
- CVE-2026-75919
- CVE-2026-75854
- CVE-2026-75852
- CVE-2026-75774
- CVE-2026-75773
- CVE-2026-75627
- CVE-2026-75514
- CVE-2026-75479
- CVE-2026-75060
- CVE-2026-75045
- CVE-2026-74981
- CVE-2026-74974
- CVE-2026-74970
- CVE-2026-74968
- CVE-2026-74967
- CVE-2026-74963
- CVE-2026-74962
- CVE-2026-74960
- CVE-2026-74934
- CVE-2026-74894
- CVE-2026-74893
- CVE-2026-74892
- CVE-2026-74891
- CVE-2026-74868
- CVE-2026-74802
- CVE-2026-74245
- CVE-2026-74243
- CVE-2026-74240
- CVE-2026-74001
- CVE-2026-73995
- CVE-2026-73849
- CVE-2026-73847
- CVE-2026-73843
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1442).