Identification & Authentication Failures
Weak auth - credential stuffing, weak reset flows, poor session handling, and bypassable MFA.
OWASP rank: 7
Practical checks
- Test password reset for host-header/token flaws
- Check for missing rate limits on login/OTP
- Review session fixation and logout behavior
- Probe MFA bypass paths