CWE-304
Missing Critical Step in Authentication
Description
The product implements an authentication technique, but it skips a step that weakens the technique.
Hierarchy (View 1000)
CVEs mapped to this weakness (40)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22833 | Hig | 0.49 | 7.6 | 0.00 | Jun 6, 2023 | Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances. | ||
| CVE-2025-55138 | Hig | 0.48 | 7.4 | 0.00 | Aug 7, 2025 | LinkJoin through 882f196 mishandles token ownership in password reset. | ||
| CVE-2023-52424 | Hig | 0.48 | 7.4 | 0.01 | May 17, 2024 | The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always… | ||
| CVE-2026-57915 | Hig | 0.47 | 7.3 | 0.00 | Jun 26, 2026 | It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue. | ||
| CVE-2024-52965 | Hig | 0.47 | 7.2 | 0.00 | Jul 8, 2025 | A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20… | ||
| CVE-2024-12136 | Med | 0.45 | 6.9 | 0.00 | Mar 19, 2025 | Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass. This issue affects ANKA JPD-00028: before V.01.01. | ||
| CVE-2022-3916 | Med | 0.44 | 6.8 | 0.01 | Sep 20, 2023 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This… | ||
| CVE-2024-7745 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2024 | In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only. | ||
| CVE-2026-55957 | Hig | 0.41 | 7.3 | 0.03 | Jun 29, 2026 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4,… | ||
| CVE-2026-40542 | Hig | 0.40 | 7.3 | 0.00 | Apr 22, 2026 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue. | ||
| CVE-2025-43014 | Med | 0.40 | 6.1 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | ||
| CVE-2025-43798 | Med | 0.35 | 6.5 | 0.00 | Sep 15, 2025 | Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as… | ||
| CVE-2023-3628 | Med | 0.35 | 6.5 | 0.01 | Dec 18, 2023 | A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions. | ||
| CVE-2011-3172 | Med | 0.35 | 5.4 | 0.01 | Jun 8, 2018 | A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12. | ||
| CVE-2025-5715 | Low | 0.25 | 3.8 | 0.00 | Jun 6, 2025 | A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch… | ||
| CVE-2023-3629 | Med | 0.21 | 4.3 | 0.01 | Dec 18, 2023 | A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions. | ||
| CVE-2026-61143 | Med | 0.00 | 6.4 | 0.00 | Jul 21, 2026 | Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network… | ||
| CVE-2022-39360 | Med | 0.00 | 6.5 | 0.01 | Oct 26, 2022 | Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is… | ||
| CVE-2022-2821 | Hig | 0.00 | 7.5 | 0.01 | Aug 15, 2022 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | ||
| CVE-2021-41179 | Med | 0.00 | 6.5 | 0.01 | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as `@PublicPage` could thus be accessed with a valid user… |
- risk 0.49cvss 7.6epss 0.00
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.
- risk 0.48cvss 7.4epss 0.00
LinkJoin through 882f196 mishandles token ownership in password reset.
- risk 0.48cvss 7.4epss 0.01
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always…
- risk 0.47cvss 7.3epss 0.00
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
- risk 0.47cvss 7.2epss 0.00
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20…
- risk 0.45cvss 6.9epss 0.00
Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass. This issue affects ANKA JPD-00028: before V.01.01.
- risk 0.44cvss 6.8epss 0.01
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This…
- risk 0.42cvss 6.5epss 0.00
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
- risk 0.41cvss 7.3epss 0.03
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4,…
- risk 0.40cvss 7.3epss 0.00
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
- risk 0.40cvss 6.1epss 0.00
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
- risk 0.35cvss 6.5epss 0.00
Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as…
- risk 0.35cvss 6.5epss 0.01
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
- risk 0.35cvss 5.4epss 0.01
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
- risk 0.25cvss 3.8epss 0.00
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch…
- risk 0.21cvss 4.3epss 0.01
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
- risk 0.00cvss 6.4epss 0.00
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network…
- risk 0.00cvss 6.5epss 0.01
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is…
- risk 0.00cvss 7.5epss 0.01
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
- risk 0.00cvss 6.5epss 0.01
Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as `@PublicPage` could thus be accessed with a valid user…