Threadlinqs IntelligenceStart free

Weakness · ClassCWE-1390

CWE-1390: Weak Authentication

Class

As of 2026-10-05, CWE-1390 (Weak Authentication) underlies 5 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 24 tracked threats.

CVEs
5Mapped to CWE-1390
CISA KEV
0None listed yet
Critical
4CVSS v3 critical CVEs
Threats
24Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-1390?

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Attackers may be able to bypass weak authentication faster and/or with less effort than expected.

CWE-1390 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; ICS/OT; Not Technology-Specific.

Source: MITRE CWE (CWE-1390 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Confidentiality, Availability, Access Control — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands. This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Source: MITRE CWE, common consequences.

How CWE-1390 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-1390, published between 2026-01-28 and 2026-08-25. None of them is in the CISA KEV catalog yet, although 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 critical. The highest EPSS score in the set is 7.4% (CVE-2025-40552), the modelled probability of exploitation in the next 30 days. 24 tracked threats reference CWE-1390 directly or through a CVE it covers; the most recent is “Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw” (2026-10-03). Affected products concentrate in Solarwinds (2), Microsoft (1), Quanovate Tech Inc. (operating as Mira / Mira Care) (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-1390, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

24 tracked threats cite CWE-1390: