# CWE-290: Authentication Bypass by Spoofing

> As of 2026-10-05, CWE-290 (Authentication Bypass by Spoofing) underlies 12 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 52 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-290?

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

CWE-290 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/290.html) (CWE-290 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism, Gain Privileges or Assume Identity. This weakness can allow an attacker to access resources which are not otherwise accessible without proper authentication.

_Source: MITRE CWE, common consequences._

## How CWE-290 is exploited in the wild

Threadlinqs maps 12 CVEs to CWE-290, published between 2021-04-27 and 2026-09-17. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 critical, 5 high, 1 medium. The highest EPSS score in the set is 83.4% (CVE-2021-29441), the modelled probability of exploitation in the next 30 days. 52 tracked threats reference CWE-290 directly or through a CVE it covers; the most recent is “Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC” (2026-10-04). Affected products concentrate in WWBN (2), CoreWCF (1), Microsoft (1), among 11 vendors in total.

## Vulnerabilities (CVEs)

All 12 CVEs mapped to CWE-290, CISA KEV first, then by CVSS score.

- [CVE-2026-54782](https://intel.threadlinqs.com/cve/CVE-2026-54782) — CVSS 10 critical · EPSS 0.2% · published 2026-07-08
- [CVE-2026-55652](https://intel.threadlinqs.com/cve/CVE-2026-55652) — CVSS 9.8 critical · EPSS 0.3% · published 2026-07-15
- [CVE-2026-84479](https://intel.threadlinqs.com/cve/CVE-2026-84479) — CVSS 9.1 critical · EPSS 0.3% · published 2026-09-01
- [CVE-2026-77903](https://intel.threadlinqs.com/cve/CVE-2026-77903) — CVSS 9 critical · EPSS 0.3% · published 2026-09-17
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441) — CVSS 8.6 high · EPSS 83.4% · published 2021-04-27
- [CVE-2026-7656](https://intel.threadlinqs.com/cve/CVE-2026-7656) — CVSS 8.1 high · EPSS 0.2% · published 2026-06-29
- [CVE-2026-56020](https://intel.threadlinqs.com/cve/CVE-2026-56020) — CVSS 8.1 high · published 2026-06-18
- [CVE-2026-84476](https://intel.threadlinqs.com/cve/CVE-2026-84476) — CVSS 7.5 high · EPSS 0.2% · published 2026-09-01
- [CVE-2026-67558](https://intel.threadlinqs.com/cve/CVE-2026-67558) — CVSS 7.4 high · EPSS 0.1% · published 2026-08-11
- [CVE-2026-73840](https://intel.threadlinqs.com/cve/CVE-2026-73840) — CVSS 5.3 medium · EPSS 0.2% · published 2026-08-13
- [CVE-2026-54308](https://intel.threadlinqs.com/cve/CVE-2026-54308) — EPSS 0.4% · published 2026-06-23
- [CVE-2026-77337](https://intel.threadlinqs.com/cve/CVE-2026-77337) — EPSS 0.3% · published 2026-08-24

## Affected vendors

- [WWBN](https://intel.threadlinqs.com/vendors/wwbn) — 2 CVEs
- [CoreWCF](https://intel.threadlinqs.com/vendors/corewcf) — 1 CVE
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- [Quanovate Tech Inc. (operating as Mira / Mira Care)](https://intel.threadlinqs.com/vendors/quanovate-tech-inc-operating-as-mira-mira-care) — 1 CVE
- **Webmin** — 1 CVE
- **alibaba** — 1 CVE
- **cakephp** — 1 CVE
- [n8n-io](https://intel.threadlinqs.com/vendors/n8n-io) — 1 CVE
- [openchoreo](https://intel.threadlinqs.com/vendors/openchoreo) — 1 CVE
- [wekan](https://intel.threadlinqs.com/vendors/wekan) — 1 CVE
- [zephyrproject](https://intel.threadlinqs.com/vendors/zephyrproject) — 1 CVE

## Threat activity

52 tracked threats cite CWE-290; the 25 most recent are listed.

- [Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC](https://intel.threadlinqs.com/threat/TL-2026-2891) — MEDIUM · 2026-10-04
- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)](https://intel.threadlinqs.com/threat/TL-2026-2880) — HIGH · 2026-10-03
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse](https://intel.threadlinqs.com/threat/TL-2026-2650) — CRITICAL · 2026-09-25
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)](https://intel.threadlinqs.com/threat/TL-2026-2563) — CRITICAL · 2026-09-18
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH · 2026-09-04
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH · 2026-08-21
- [Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchases](https://intel.threadlinqs.com/threat/TL-2026-2102) — HIGH · 2026-08-21
- [Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains](https://intel.threadlinqs.com/threat/TL-2026-2050) — HIGH · 2026-08-17
- [Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)](https://intel.threadlinqs.com/threat/TL-2026-2024) — HIGH · 2026-08-15
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens](https://intel.threadlinqs.com/threat/TL-2026-1808) — HIGH · 2026-07-31
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal Sector](https://intel.threadlinqs.com/threat/TL-2026-1777) — HIGH · 2026-07-30
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — HIGH · 2026-07-29
- [InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)](https://intel.threadlinqs.com/threat/TL-2026-1679) — HIGH · 2026-07-25
- [ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation Attempts](https://intel.threadlinqs.com/threat/TL-2026-1665) — MEDIUM · 2026-07-24
- [German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft](https://intel.threadlinqs.com/threat/TL-2026-1602) — HIGH · 2026-07-22
- [German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA](https://intel.threadlinqs.com/threat/TL-2026-1612) — HIGH · 2026-07-22
- [Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA](https://intel.threadlinqs.com/threat/TL-2026-1584) — HIGH · 2026-07-21
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions](https://intel.threadlinqs.com/threat/TL-2026-1593) — HIGH · 2026-07-21
- [MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne Pages](https://intel.threadlinqs.com/threat/TL-2026-1522) — HIGH · 2026-07-19
- [CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-1434) — CRITICAL · 2026-07-17
- [CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1378) — CRITICAL · 2026-07-15
- [Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and Render to Harvest Google Workspace Credentials and Bypass MFA](https://intel.threadlinqs.com/threat/TL-2026-1388) — HIGH · 2026-07-15
- [New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential Harvesting](https://intel.threadlinqs.com/threat/TL-2026-1306) — HIGH · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)](https://intel.threadlinqs.com/threat/TL-2026-1325) — CRITICAL · 2026-07-14
- [WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage Targeting 1.4M Domains via CVE-2026-48907 (Joomla JCE) and CVE-2021-29441 (Nacos)](https://intel.threadlinqs.com/threat/TL-2026-1180) — HIGH · 2026-07-10

## Related weaknesses

- [CWE-1390 Weak Authentication](https://intel.threadlinqs.com/cwe/CWE-1390)
- [CWE-287 Improper Authentication](https://intel.threadlinqs.com/cwe/CWE-287)

Canonical: https://intel.threadlinqs.com/cwe/CWE-290
Source definition: https://cwe.mitre.org/data/definitions/290.html
Detection rules and IOCs for threats exploiting CWE-290 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
