What is CWE-1390?
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Attackers may be able to bypass weak authentication faster and/or with less effort than expected.
CWE-1390 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; ICS/OT; Not Technology-Specific.
Source: MITRE CWE (CWE-1390 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Confidentiality, Availability, Access Control — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands. This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Source: MITRE CWE, common consequences.
How CWE-1390 is exploited in the wild
Threadlinqs maps 5 CVEs to CWE-1390, published between 2026-01-28 and 2026-08-25. None of them is in the CISA KEV catalog yet, although 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 critical. The highest EPSS score in the set is 7.4% (CVE-2025-40552), the modelled probability of exploitation in the next 30 days. 24 tracked threats reference CWE-1390 directly or through a CVE it covers; the most recent is “Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw” (2026-10-03). Affected products concentrate in Solarwinds (2), Microsoft (1), Quanovate Tech Inc. (operating as Mira / Mira Care) (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 5 CVEs mapped to CWE-1390, CISA KEV first, then by CVSS score.
- CVE-2025-40552 — CVSS 9.8 critical · EPSS 7.4% · published 2026-01-28
- CVE-2025-40554 — CVSS 9.8 critical · EPSS 6.0% · published 2026-01-28
- CVE-2026-68067 — CVSS 9.8 critical · EPSS 0.2% · published 2026-08-11
- CVE-2026-55040 — CVSS 9.1 critical · published 2026-07-14
- CVE-2026-44476 — published 2026-08-25
Affected vendors
- Solarwinds — 2 CVEs
- Microsoft — 1 CVE
- Quanovate Tech Inc. (operating as Mira / Mira Care) — 1 CVE
- doorkeeper-gem — 1 CVE
Threat activity
24 tracked threats cite CWE-1390:
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization FlawHIGH
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CatalogCRITICAL
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-DaysCRITICAL
- CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Exploited in the WildCRITICAL
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)CRITICAL
- Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical RCE Pair in July 2026 Patch TuesdayCRITICAL
- CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEVCRITICAL
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)CRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege EscalationCRITICAL
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)CRITICAL
- July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040HIGH
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)CRITICAL
- O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack Enterprise AccountsHIGH
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365)HIGH
- Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & GmailHIGH
- Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS)HIGH
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)HIGH
- VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)HIGH
- Tycoon 2FA Adopts OAuth 2.0 Device-Code Phishing — PhaaS Kit Hijacks Microsoft 365 Accounts via Microsoft Authentication Broker (AppId 29d9ed98) Through Trustifi Click-Tracking and Cloudflare Workers Delivery (eSentire TRU TL-2026-0522)HIGH
- SolarWinds Web Help Desk Pre-Auth RCE Chain (CVE-2025-40552, CVE-2025-40553, CVE-2025-40554)CRITICAL