The product implements an authentication technique, but it skips a step that weakens the technique.
Volume of CVEs assigned to CWE-304 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55957HIGH Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate withou | Jun 29, 2026 | 7.3 | 38 | NO | NO |
CVE-2026-44547CRITICAL ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from | May 12, 2026 | 9.6 | 36 | NO | NO |
CVE-2026-57915HIGH It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to ve | Jun 26, 2026 | 7.3 | 34 | NO | NO |
CVE-2025-24322CRITICAL An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lea | Aug 20, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-42452HIGH Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_toke | May 8, 2026 | 8.1 | 32 | NO | NO |
CVE-2024-2172CRITICAL The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on th | Mar 13, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-2302CRITICAL Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full a | Jul 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-40542HIGH Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication | Apr 22, 2026 | 7.3 | 29 | NO | NO |
CVE-2026-30831CRITICAL Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnera | Mar 6, 2026 | 9.8 | 29 | NO | NO |
CVE-2024-45764CRITICAL Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentia | Nov 8, 2024 | 9.8 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.