Common Weakness Enumeration

    CWE Definition / CWE-302

    CWE-302: Authentication Bypass by Assumed-Immutable Data

    The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-1390: Weak Authentication

    CWE-807: Reliance on Untrusted Inputs in a Security Decision