CWE-308: Use of Single-factor Authentication
The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.
14 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-64103 — Zitadel Bypass Second Authentication Factor
- CVE-2026-58240 — Missing Authentication check in SAP NetWeaver (Message Server)
- CVE-2025-42959 — Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476
- CVE-2024-47652 — Insecure Authentication Vulnerability
- CVE-2026-67611 — OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
- CVE-2026-45749 — Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
- CVE-2026-85590 — phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
- CVE-2026-56022 — Webmin MFA bypass
- CVE-2024-27928 — Vantage6: 2FA can be circumvented with hacked email access
- CVE-2026-33550 — SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits inst
Recently published
- CVE-2026-58240 — Missing Authentication check in SAP NetWeaver (Message Server)
- CVE-2026-85590 — phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
- CVE-2026-67611 — OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
- CVE-2026-56022 — Webmin MFA bypass
- CVE-2024-27928 — Vantage6: 2FA can be circumvented with hacked email access
- CVE-2026-45749 — Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
- CVE-2026-33550 — SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits inst
- CVE-2025-64103 — Zitadel Bypass Second Authentication Factor
- CVE-2025-42959 — Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476
- CVE-2024-47652 — Insecure Authentication Vulnerability