CWE-303— Incorrect Implementation of Authentication Algorithm
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.— MITRE CWE catalog
110 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-303page 3 of 3
- CVE-2026-59309CRITICALCVSS 9.8EG 9.82026-07-30
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
- CVE-2026-66028MEDIUMCVSS 6.7EG 6.72026-07-27
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers ca…
- CVE-2026-66411MEDIUMCVSS 5.3EG 5.32026-08-10
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot.
- CVE-2026-73444MEDIUMCVSS 4.7EG 4.72026-09-15
On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authenticati…
- CVE-2026-73458HIGHCVSS 8.2EG 8.22026-09-15
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes be…
- CVE-2026-78629MEDIUMCVSS 5.6EG 5.62026-09-08
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptograph…
- CVE-2026-8922MEDIUMCVSS 5.4EG 5.42026-05-19
A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens …
- CVE-2026-93394LOWCVSS 3.7EG 3.72026-09-17
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party…
- CVE-2026-9853HIGHCVSS 7.8EG 7.82026-09-03
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SY…
- CVE-2026-9854HIGHCVSS 7.8EG 7.82026-09-03
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
Map vulnerabilities like CWE-303 to your infrastructure
EchelonGraph correlates every CVE — across CWE-303 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →