CWE-303— Incorrect Implementation of Authentication Algorithm
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-303page 1 of 3
- CVE-2024-7593CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-13
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
- CVE-2023-29357CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-14
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2026-77244CRITICALCVSS 10.0EG 10.02026-09-22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to th…
- CVE-2026-46595CRITICALCVSS 10.0EG 10.02026-05-22
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
- CVE-2025-13390CRITICALCVSS 10.0EG 10.02025-12-03
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. Th…
- CVE-2022-20695CRITICALCVSS 10.0EG 10.02022-04-15
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface…
- CVE-2025-12421CRITICALCVSS 9.9EG 9.92025-11-27
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user…
- CVE-2025-12419CRITICALCVSS 9.9EG 9.92025-11-27
Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation pri…
- CVE-2022-39366CRITICALCVSS 9.9EG 9.92022-10-28
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as…
- CVE-2026-59309CRITICALCVSS 9.8EG 9.82026-07-30
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
- CVE-2026-12773CRITICALCVSS 9.8EG 9.82026-06-21
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation c…
- CVE-2026-46389CRITICALCVSS 9.8EG 9.82026-06-05
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak c…
- CVE-2026-35579CRITICALCVSS 9.8EG 9.82026-05-05
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in th…
- CVE-2026-29515CRITICALCVSS 9.8EG 9.82026-03-11
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinati…
- CVE-2026-28446CRITICALCVSS 9.8EG 9.82026-03-05
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching inst…
- CVE-2025-66489CRITICALCVSS 9.8EG 9.82025-12-03
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts.…
- CVE-2025-63210CRITICALCVSS 9.8EG 9.82025-11-19
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By…
- CVE-2025-21311CRITICALCVSS 9.8EG 9.82025-01-14
Windows NTLM V1 Elevation of Privilege Vulnerability
- CVE-2024-10127CRITICALCVSS 9.8EG 9.82024-11-20
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable co…
- CVE-2024-4985CRITICALCVSS 9.8EG 9.82024-05-20
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a S…
- CVE-2023-3326CRITICALCVSS 9.8EG 9.82023-06-22
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is…
- CVE-2018-4841CRITICALCVSS 9.8EG 9.82018-03-29
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful …
- CVE-2020-37094CRITICALCVSS 8.1EG 9.82026-02-03
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentic…
- CVE-2022-20923CRITICALCVSS 4.0EG 9.82022-09-08
A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec V…
- CVE-2023-4860CRITICALCVSS 9.6EG 9.62024-07-16
Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: H…
- CVE-2024-4332CRITICALCVSS 9.3EG 9.32024-06-03
An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP…
- CVE-2026-15688CRITICALCVSS 9.2EG 9.22026-09-17
Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affect…
- CVE-2026-3869CRITICALCVSS 9.2EG 9.22026-09-11
CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running o…
- CVE-2026-97720CRITICALCVSS 9.1EG 9.12026-10-07
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to …
- CVE-2026-10050CRITICALCVSS 9.1EG 9.12026-07-22
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be I…
- CVE-2026-50627CRITICALCVSS 9.1EG 9.12026-06-12
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resour…
- CVE-2026-41103CRITICALCVSS 9.1EG 9.12026-05-12
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-33557CRITICALCVSS 9.1EG 9.12026-04-20
A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JW…
- CVE-2023-29129CRITICALCVSS 9.1EG 9.12023-06-13
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 …
- CVE-2023-25957CRITICALCVSS 9.1EG 9.12023-03-14
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All ver…
- CVE-2020-8863CRITICALCVSS 8.8EG 9.02020-03-23
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. Th…
- CVE-2026-107279HIGHCVSS 8.8EG 8.82026-10-07
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipp…
- CVE-2026-49467HIGHCVSS 8.8EG 8.82026-08-12
Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root…
- CVE-2026-47300HIGHCVSS 8.8EG 8.82026-07-14
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50360HIGHCVSS 8.8EG 8.82026-07-14
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-41053HIGHCVSS 8.8EG 8.82026-06-30
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
- CVE-2026-0073HIGHCVSS 8.8EG 8.82026-05-04
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execu…
- CVE-2025-4676HIGHCVSS 8.8EG 8.82026-01-07
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: thro…
- CVE-2024-34722HIGHCVSS 8.8EG 8.82024-07-09
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges ne…
- CVE-2023-44420HIGHCVSS 8.8EG 8.82024-05-03
D-Link DIR-X3260 prog.cgi Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-X3260…
- CVE-2023-34282HIGHCVSS 8.8EG 8.82024-05-03
D-Link DIR-2150 HNAP Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2150 route…
- CVE-2023-34274HIGHCVSS 8.8EG 8.82024-05-03
D-Link DIR-2150 LoginPassword Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2…
- CVE-2023-31211HIGHCVSS 8.8EG 8.82024-01-12
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
- CVE-2021-32691HIGHCVSS 8.8EG 8.82021-06-16
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday…
- CVE-2020-15632HIGHCVSS 8.8EG 8.82020-07-23
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the pr…
Map vulnerabilities like CWE-303 to your infrastructure
EchelonGraph correlates every CVE — across CWE-303 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →