CWE•Base•Incomplete•14 recent CVEs
CWE-302Authentication Bypass by Assumed-Immutable Data
Description
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
Common consequences
- Access Control→Bypass Protection Mechanism
Potential mitigations
- Architecture and Design,Operation,ImplementationImplement proper protection for immutable data (e.g. environment variable, hidden form fields, etc.)
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-775083.52026-08-26CVE-2026-132678.12026-08-12CVE-2026-54232026-08-06CVE-2026-505288.22026-07-14CVE-2026-473038.82026-07-14CVE-2026-481176.82026-06-17CVE-2026-487819.92026-06-17CVE-2026-344605.42026-06-02CVE-2025-439925.62026-05-11CVE-2026-285105.92026-05-05CVE-2026-394298.22026-04-08CVE-2025-88558.12025-11-14CVE-2024-84756.52024-12-17CVE-2023-46699.82023-09-14