Threadlinqs IntelligenceStart free

Weakness · BaseCWE-290

CWE-290: Authentication Bypass by Spoofing

Base

As of 2026-10-05, CWE-290 (Authentication Bypass by Spoofing) underlies 12 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 52 tracked threats.

CVEs
12Mapped to CWE-290
CISA KEV
0None listed yet
Critical
4CVSS v3 critical CVEs
Threats
52Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-290?

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

CWE-290 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-290 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism, Gain Privileges or Assume Identity. This weakness can allow an attacker to access resources which are not otherwise accessible without proper authentication.

Source: MITRE CWE, common consequences.

How CWE-290 is exploited in the wild

Threadlinqs maps 12 CVEs to CWE-290, published between 2021-04-27 and 2026-09-17. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 critical, 5 high, 1 medium. The highest EPSS score in the set is 83.4% (CVE-2021-29441), the modelled probability of exploitation in the next 30 days. 52 tracked threats reference CWE-290 directly or through a CVE it covers; the most recent is “Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC” (2026-10-04). Affected products concentrate in WWBN (2), CoreWCF (1), Microsoft (1), among 11 vendors in total.

Vulnerabilities (CVEs)

All 12 CVEs mapped to CWE-290, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

52 tracked threats cite CWE-290; the 25 most recent are listed.