On this page

CWE-290: Authentication Bypass by Spoofing

Weakness Summary

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

  • Canonical source: MITRE CWE-290 (opens in a new tab)
  • Published Atomicorp CVE observations: 3
  • Distinct affected products in those observations: 3
  • Active Atomicorp rules associated with this weakness: 6

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2022-24112Apache APISIX - Remote Code ExecutionapisixAttack Blocked by Atomicorp344364 , 344366 , 344370
CVE-2025-49002DataEase - Remote Code ExecutiondataeaseAttack Blocked by Atomicorp340195
CVE-2021-31195Microsoft Exchange Server - Cross-Site Scriptingexchange serverAttack Blocked by Atomicorp346755 , 350148

Associated Atomicorp WAF Rules

RuleStatusBehavior
340195Activedisruptive (deny)
344364Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
346755Activedisruptive (deny)
350148Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-21 (opens in a new tab) , CAPEC-22 (opens in a new tab) , CAPEC-459 (opens in a new tab) , CAPEC-461 (opens in a new tab) , CAPEC-473 (opens in a new tab) , CAPEC-476 (opens in a new tab) , CAPEC-59 (opens in a new tab) , CAPEC-60 (opens in a new tab) , CAPEC-667 (opens in a new tab) , CAPEC-94 (opens in a new tab)