CWE-304: Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.
38 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2025-24322 — An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.
- CVE-2024-9216 — Authentication Bypass in gaizhenbiao/ChuanhuChatGPT
- CVE-2026-44547 — ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2
- CVE-2026-30831 — Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
- CVE-2023-54391 — Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
- CVE-2026-61466 — Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
- CVE-2026-59564 — Authentication bypass between ZCC and client connector portal
- CVE-2025-55138 — LinkJoin through 882f196 mishandles token ownership in password reset.
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-67351 — Serendipity < 2.6.1 Authentication Bypass via Username Collision
- CVE-2026-76207 — phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
- CVE-2024-52965 — A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0
- CVE-2026-42452 — Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP
- CVE-2026-40542 — Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
- CVE-2026-57915 — Apache Kerby: Kerberos Pre-Authentication Bypass
- CVE-2025-43014 — In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
- CVE-2024-12136 — Improper Access Control in Elfatek Elektronics' ANKA JPD-00028
- CVE-2025-5715 — Signal App Biometric Authentication missing critical step in authentication
Recently published
- CVE-2023-54391 — Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
- CVE-2026-59564 — Authentication bypass between ZCC and client connector portal
- CVE-2026-76207 — phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-61466 — Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
- CVE-2026-67351 — Serendipity < 2.6.1 Authentication Bypass via Username Collision
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2026-57915 — Apache Kerby: Kerberos Pre-Authentication Bypass
- CVE-2026-44547 — ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2
- CVE-2026-42452 — Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP
- CVE-2026-40542 — Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
- CVE-2026-30831 — Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
- CVE-2025-43798 — Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-
- CVE-2025-24322 — An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.
- CVE-2025-55138 — LinkJoin through 882f196 mishandles token ownership in password reset.
- CVE-2024-52965 — A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0
- CVE-2025-5715 — Signal App Biometric Authentication missing critical step in authentication
- CVE-2025-43014 — In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
- CVE-2024-9216 — Authentication Bypass in gaizhenbiao/ChuanhuChatGPT
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi