CWE-1390
CVEs classified under CWE-1390, newest first.
10 CVEsRSS
CVE-2026-77483High· 8.8Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-73025Critical· 9.8Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62895High· 8.8Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-80219High· 8.7Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2026-44476Medium· 6.3PoCDoorkeeper is an OAuth 2 provider for Ruby on Rails
Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain …
CVE-2026-59135Medium· 5.5Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CVE-2026-55040Critical· 9.1CISA KEVPoCMicrosoft SharePoint Server Security Feature Bypass Vulnerability
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-0274Critical· 9.1An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
CVE-2026-1693High· 7.5The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…
CVE-2024-35248High· 7.3Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability