What is CWE-290?
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-290 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-290 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Bypass Protection Mechanism, Gain Privileges or Assume Identity. This weakness can allow an attacker to access resources which are not otherwise accessible without proper authentication.
Source: MITRE CWE, common consequences.
How CWE-290 is exploited in the wild
Threadlinqs maps 12 CVEs to CWE-290, published between 2021-04-27 and 2026-09-17. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 critical, 5 high, 1 medium. The highest EPSS score in the set is 83.4% (CVE-2021-29441), the modelled probability of exploitation in the next 30 days. 52 tracked threats reference CWE-290 directly or through a CVE it covers; the most recent is “Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC” (2026-10-04). Affected products concentrate in WWBN (2), CoreWCF (1), Microsoft (1), among 11 vendors in total.
Vulnerabilities (CVEs)
All 12 CVEs mapped to CWE-290, CISA KEV first, then by CVSS score.
- CVE-2026-54782 — CVSS 10 critical · EPSS 0.2% · published 2026-07-08
- CVE-2026-55652 — CVSS 9.8 critical · EPSS 0.3% · published 2026-07-15
- CVE-2026-84479 — CVSS 9.1 critical · EPSS 0.3% · published 2026-09-01
- CVE-2026-77903 — CVSS 9 critical · EPSS 0.3% · published 2026-09-17
- CVE-2021-29441 — CVSS 8.6 high · EPSS 83.4% · published 2021-04-27
- CVE-2026-7656 — CVSS 8.1 high · EPSS 0.2% · published 2026-06-29
- CVE-2026-56020 — CVSS 8.1 high · published 2026-06-18
- CVE-2026-84476 — CVSS 7.5 high · EPSS 0.2% · published 2026-09-01
- CVE-2026-67558 — CVSS 7.4 high · EPSS 0.1% · published 2026-08-11
- CVE-2026-73840 — CVSS 5.3 medium · EPSS 0.2% · published 2026-08-13
- CVE-2026-54308 — EPSS 0.4% · published 2026-06-23
- CVE-2026-77337 — EPSS 0.3% · published 2026-08-24
Affected vendors
- WWBN — 2 CVEs
- CoreWCF — 1 CVE
- Microsoft — 1 CVE
- Quanovate Tech Inc. (operating as Mira / Mira Care) — 1 CVE
- Webmin — 1 CVE
- alibaba — 1 CVE
- cakephp — 1 CVE
- n8n-io — 1 CVE
- openchoreo — 1 CVE
- wekan — 1 CVE
- zephyrproject — 1 CVE
Threat activity
52 tracked threats cite CWE-290; the 25 most recent are listed.
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARCMEDIUM
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)HIGH
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow AbuseCRITICAL
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)CRITICAL
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web serversHIGH
- Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card PurchasesHIGH
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack ChainsHIGH
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)HIGH
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 TokensHIGH
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal SectorHIGH
- AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session TheftHIGH
- InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)HIGH
- ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation AttemptsMEDIUM
- German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie TheftHIGH
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFAHIGH
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFAHIGH
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational InstitutionsHIGH
- MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne PagesHIGH
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CatalogCRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and Render to Harvest Google Workspace Credentials and Bypass MFAHIGH
- New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential HarvestingHIGH
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)CRITICAL
- WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage Targeting 1.4M Domains via CVE-2026-48907 (Joomla JCE) and CVE-2021-29441 (Nacos)HIGH