Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-1390'

View all threats tagged with 'cwe-1390'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1390

Threats Tagged 'cwe-1390'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-68067: CWE-1390 Weak Authentication in Quanovate Tech Inc. (operating as Mira / Mira Care) Mira FirmwareCVE-2026-68067
0

CVE-2026-68067 is a critical authentication vulnerability in Mira Firmware by Quanovate Tech Inc. The login endpoint accepts any format-valid string as a password and returns an active session token for the account matching the provided email address. This flaw allows attackers to gain unauthorized access to cloud accounts, including sensitive hormone record information and account settings. The vulnerability affects version 1.7.1.47 of the Mira Firmware. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-59135: CWE-1390: Weak Authentication in Microsoft Windows 10 Version 1607CVE-2026-59135
0

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Join the discussion
CVE-2026-50756: n/aCVE-2026-50756
0

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

Join the discussion
CVE-2026-55040: CWE-1390: Weak Authentication in Microsoft Microsoft SharePoint Enterprise Server 2016CVE-2026-55040
0

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Join the discussion
CVE-2026-10714: CWE-1390: Weak Authentication in Rockwell Automation FactoryTalk® Services PlatformCVE-2026-10714
0

A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cwe-1390
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses