Common Weakness Enumeration

    CWE Definition / CWE-1390

    CWE-1390: Weak Authentication

    The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

    Published:5 Oct 2022
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-287: Improper Authentication