Threats Tagged 'cwe-1390'
View all threats tagged with 'cwe-1390'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1390'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-68067: CWE-1390 Weak Authentication in Quanovate Tech Inc. (operating as Mira / Mira Care) Mira FirmwareCVE-2026-68067 0 CVE-2026-68067 is a critical authentication vulnerability in Mira Firmware by Quanovate Tech Inc. The login endpoint accepts any format-valid string as a password and returns an active session token for the account matching the provided email address. This flaw allows attackers to gain unauthorized access to cloud accounts, including sensitive hormone record information and account settings. The vulnerability affects version 1.7.1.47 of the Mira Firmware. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/11/2026, 21:23:05 UTC Added: 08/11/2026, 21:26:47 UTC |
CVE-2026-59135: CWE-1390: Weak Authentication in Microsoft Windows 10 Version 1607CVE-2026-59135 0 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 08/11/2026, 17:03:45 UTC Added: 08/11/2026, 17:12:30 UTC |
CVE-2026-50756: n/aCVE-2026-50756 0 An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component Join the discussion | GCVE Database | 07/21/2026, 00:00:00 UTC Added: 07/22/2026, 00:11:22 UTC |
CVE-2026-55040: CWE-1390: Weak Authentication in Microsoft Microsoft SharePoint Enterprise Server 2016CVE-2026-55040 0 Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. Join the discussion | CVE Database V5 | 07/14/2026, 17:09:00 UTC Added: 07/14/2026, 17:49:37 UTC |
CVE-2026-10714: CWE-1390: Weak Authentication in Rockwell Automation FactoryTalk® Services PlatformCVE-2026-10714 0 A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. Join the discussion | CVE Database V5 | 07/14/2026, 15:02:09 UTC Added: 07/14/2026, 15:18:23 UTC |
Showing 1 to 5 of 5 results