CWE-304Base

Missing Critical Step in Authentication

Draft in the CWE catalog · 39 CVEs mapped

39
CVEs mapped
8.0
Median CVSS
What it is

The product implements an authentication technique, but it skips a step that weakens the technique.

Recent examples
9.8cvss
CVE-2023-54391

CVE-2023-54391 - CRITICAL Severity Vulnerability

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

CRITICALno explanation yet
0%
epss
9.1cvss
CVE-2026-59564

CVE-2026-59564 - CRITICAL Severity Vulnerability

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

CRITICALno explanation yet
0%
epss
8.1cvss
CVE-2026-76207

CVE-2026-76207 - HIGH Severity Vulnerability

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-304
Abstraction
Base
Structure
Simple
Status
Draft