Skip to main content
JG is here with you ✨
A07:2025

Authentication Failures

Identification & Authentication Flaws

Identity Focus

What are Authentication Failures?

Authentication failures occur when applications incorrectly confirm user identity. This includes weak passwords, credential stuffing, brute force attacks, poor session management, and missing or bypassable MFA.

Formerly "Broken Authentication"Credential AttacksSession Hijacking

Brute Force

Automated password guessing attacks

Credential Stuffing

Using leaked credentials from breaches

Weak Passwords

Common or easily guessable passwords

Session Hijacking

Stealing or fixating session tokens

MFA Bypass

Circumventing multi-factor authentication

Password Recovery

Weak reset mechanisms

Related CWE Entries

Built by an OWASP Member • Part of the OWASP Web Security Lab Series

Open to AI-Focused Roles

AI Sales • AI Strategy • AI Success • Creative Tech • Toronto / Remote

Let's connect →
Terms of ServiceLicense AgreementPrivacy Policy
Copyright © 2026 JMFG. All rights reserved.