CWE-303— Incorrect Implementation of Authentication Algorithm
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-303page 2 of 3
- CVE-2020-8861HIGHCVSS 8.8EG 8.82020-02-22
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw …
- CVE-2022-41985HIGHCVSS 8.6EG 8.62023-05-10
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can sen…
- CVE-2025-53782HIGHCVSS 7.8EG 8.42025-10-14
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-73458HIGHCVSS 8.2EG 8.22026-09-15
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes be…
- CVE-2021-21378HIGHCVSS 8.2EG 8.22021-03-11
Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication fil…
- CVE-2026-43640HIGHCVSS 8.1EG 8.12026-05-11
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only …
- CVE-2025-14510HIGHCVSS 8.1EG 8.12026-01-16
Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120.
- CVE-2025-57808HIGHCVSS 8.1EG 8.12025-09-02
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded A…
- CVE-2025-44557HIGHCVSS 8.1EG 8.12025-06-27
A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication via a crafted pairing_failed packet.
- CVE-2024-8642HIGHCVSS 8.1EG 8.12024-09-11
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass…
- CVE-2021-21902HIGHCVSS 8.1EG 8.12021-12-22
An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via session hijacking. An at…
- CVE-2016-9463HIGHCVSS 8.1EG 8.12017-03-28
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allo…
- CVE-2026-9854HIGHCVSS 7.8EG 7.82026-09-03
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
- CVE-2026-9853HIGHCVSS 7.8EG 7.82026-09-03
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SY…
- CVE-2026-101878HIGHCVSS 7.5EG 7.52026-09-29
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO l…
- CVE-2026-33190HIGHCVSS 7.5EG 7.52026-05-05
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it trusts the transport writer's TsigStatus() instead of performi…
- CVE-2025-43727HIGHCVSS 7.5EG 7.52025-10-07
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contai…
- CVE-2025-23046HIGHCVSS 7.5EG 7.52025-02-25
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone …
- CVE-2024-26248HIGHCVSS 7.5EG 7.52024-04-09
Windows Kerberos Elevation of Privilege Vulnerability
- CVE-2024-3046HIGHCVSS 7.5EG 7.52024-04-09
In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perf…
- CVE-2021-42146HIGHCVSS 7.5EG 7.52024-01-24
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulner…
- CVE-2023-5627HIGHCVSS 7.5EG 7.52023-11-01
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users…
- CVE-2022-33736HIGHCVSS 7.5EG 7.52022-07-12
A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624). The affected applications do not properly validate login information during authenticati…
- CVE-2026-92873HIGHCVSS 7.3EG 7.32026-09-30
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.
- CVE-2026-11430HIGHCVSS 7.3EG 7.32026-08-07
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-circuits and skips token validation, so a…
- CVE-2025-43856HIGHCVSS 7.3EG 7.32025-07-11
immich is a high performance self-hosted photo and video management solution. Prior to 1.132.0, immich is vulnerable to account hijacking through oauth2, because the state parameter is not being checked. The oauth2 state parameter is simil…
- CVE-2025-14273HIGHCVSS 7.2EG 7.22025-12-22
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the J…
- CVE-2026-41049HIGHCVSS 7.1EG 7.12026-06-22
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
- CVE-2026-41048HIGHCVSS 7.1EG 7.12026-06-22
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
- CVE-2025-48994MEDIUMCVSS 6.9EG 6.92025-06-02
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), ver…
- CVE-2026-66028MEDIUMCVSS 6.7EG 6.72026-07-27
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers ca…
- CVE-2019-25436MEDIUMCVSS 6.5EG 6.52026-02-20
Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the ol…
- CVE-2025-8881MEDIUMCVSS 6.5EG 6.52025-08-13
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security sev…
- CVE-2024-9999MEDIUMCVSS 6.5EG 6.52024-11-12
In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
- CVE-2024-25157MEDIUMCVSS 6.5EG 6.52024-08-14
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized informat…
- CVE-2023-32152MEDIUMCVSS 6.5EG 6.52024-05-03
D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to e…
- CVE-2023-32148MEDIUMCVSS 6.5EG 6.52024-05-03
D-Link DIR-2640 HNAP PrivateLogin Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to ex…
- CVE-2022-43635MEDIUMCVSS 6.5EG 6.52023-03-29
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific f…
- CVE-2020-5268MEDIUMCVSS 6.5EG 6.52020-04-21
In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerability in how tokens are validated in some cases. Saml2 tokens are usually used as bearer tokens - a caller that presents a …
- CVE-2025-61783MEDIUMCVSS 6.3EG 6.32025-10-09
Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to ac…
- CVE-2022-46146MEDIUMCVSS 6.2EG 6.22022-11-29
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in au…
- CVE-2026-27656MEDIUMCVSS 6.1EG 6.12026-03-25
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user acc…
- CVE-2024-35190MEDIUMCVSS 5.8EG 5.82024-05-17
Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, an…
- CVE-2026-57852MEDIUMCVSS 5.6EG 5.62026-07-20
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. A…
- CVE-2026-78629MEDIUMCVSS 5.5EG 5.62026-09-08
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptograph…
- CVE-2024-8314MEDIUMCVSS 5.5EG 5.52025-03-25
An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently a…
- CVE-2023-4641MEDIUMCVSS 5.5EG 5.52023-12-27
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an…
- CVE-2026-8922MEDIUMCVSS 5.4EG 5.42026-05-19
A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens …
- CVE-2025-3230MEDIUMCVSS 5.4EG 5.42025-05-30
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting…
- CVE-2025-2475MEDIUMCVSS 5.4EG 5.42025-04-14
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
Map vulnerabilities like CWE-303 to your infrastructure
EchelonGraph correlates every CVE — across CWE-303 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →