Threats Tagged 'cwe-1390'
View all threats tagged with 'cwe-1390'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1390'
Click on any threat for detailed analysis and mitigation recommendations
0 Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when the request carries no code_challenge, and token() admits the exchange as long as a challenge was stored or an authentication method was returned for the caller. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the method deduced from the request, so any Basic or form credential satisfies the secret branch. validatePKCEChallenge() then passes, because neither a challenge nor a verifier is present. An attacker who intercepts an authorization code issued to a public Relying Party can exchange it for the user's access, ID and refresh tokens by replaying the client_id with an arbitrary secret, which is the attack PKCE prevents. Dynamic client registration creates every Relying Party in this mode. Join the discussion | CVE Database V5 | 09/25/2026, 03:31:00 UTC Added: 09/25/2026, 01:03:20 UTC |
0 Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check. An attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers. Join the discussion | CVE Database V5 | 09/25/2026, 00:10:24 UTC Added: 09/25/2026, 01:03:20 UTC |
0 An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on that list, so no authentication runs for these routes. The endpoint's only check is that the request body carries a token bearing a valid signature from the instance secret. It does not check what that token was issued for. Login tokens are signed with the same secret and carry no purpose, audience or expiry claim, so an ordinary user's own session token satisfies the check. Presented with such a token, the endpoint creates a new organisation holding the highest subscription tier, flagged as lifetime and with a channel allowance far above any sold plan, creates an organisation-owner account alongside it, and returns the new organisation's API key in the response body. That key is immediately valid against the public API. Join the discussion | CVE Database V5 | 09/22/2026, 16:17:00 UTC Added: 09/22/2026, 16:33:28 UTC |
0 Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:12 UTC Added: 09/08/2026, 17:26:46 UTC |
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:08 UTC Added: 09/08/2026, 17:26:45 UTC |
0 Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:10:31 UTC Added: 09/08/2026, 17:24:23 UTC |
0 The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device. Join the discussion | CVE Database V5 | 08/31/2026, 15:28:32 UTC Added: 08/31/2026, 15:39:58 UTC |
0 CVE-2026-44476 is an improper authentication vulnerability in the doorkeeper-openid_connect gem version 1.9.0. It allows an attacker who knows a dynamically registered client's client_id to obtain an access token without providing the client_secret. This occurs because dynamically registered clients are incorrectly marked as non-confidential, causing the client_secret verification to be skipped. The issue affects only projects that have enabled Dynamic Client Registration, which is disabled by default. The vulnerability is fixed in version 1.10.0. Join the discussion | CVE Database V5 | 08/25/2026, 22:47:54 UTC Added: 08/25/2026, 22:53:26 UTC |
NVIDIA NemoClaw for Linux has a vulnerability in its remote-access helper workflow that results in weak authentication. Exploiting this flaw could allow an attacker to execute code, disclose information, and tamper with data. The vulnerability is identified as CWE-1390 and carries a high severity with a CVSS score of 8.1. No patch or official remediation guidance has been provided yet. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/25/2026, 20:15:22 UTC Added: 08/25/2026, 20:23:15 UTC |
0 The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings. Join the discussion | CVE Database V5 | 08/11/2026, 21:23:05 UTC Added: 08/11/2026, 21:26:47 UTC |
Showing 1 to 10 of 45 results