The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.
Volume of CVEs assigned to CWE-308 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45749HIGH Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` end | Jun 5, 2026 | 8.1 | 32 | NO | NO |
CVE-2025-64103CRITICAL Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a | Oct 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-56022MEDIUM Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.64 | Jun 18, 2026 | 5.3 | 27 | NO | NO |
CVE-2024-27928MEDIUM vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's email account, they can 1) reset the | Jun 17, 2026 | 5.9 | 25 | NO | NO |
CVE-2024-47652HIGH This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted | Oct 4, 2024 | 8.1 | 22 | NO | NO |
CVE-2023-49075HIGH The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non | Nov 28, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-34228MEDIUM In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | May 31, 2023 | 6.5 | 21 | NO | NO |
CVE-2025-42959HIGH An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reuse | Jul 8, 2025 | 8.1 | 20 | NO | NO |
CVE-2024-50618MEDIUM A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the sys | Feb 11, 2026 | 4.3 | 18 | NO | NO |
CVE-2023-25681MEDIUM LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. T | Mar 5, 2024 | 6.5 | 18 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.