Cyber Resilience

CWE · MITRE source

CWE-304Missing Critical Step in Authentication

Abstraction: Base · CVEs in our corpus: 38

The product implements an authentication technique, but it skips a step that weakens the technique.

Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.

Last updated: 20 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 3 mapping(s) from 2 framework(s): STIG rhel 7 2 (mostly) · STIG ubuntu 22 04 1 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • IA-8 Identification and Authentication (Non-organizational Users)
  • PR.AA-02
  • PR.AA-03
  • IA-2 Identification and Authentication (Organizational Users)
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V7.2.4

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
IA-8Identification and Authentication (Non-organizational Users)IAEnsures the authentication process is followed for non-organizational users, avoiding missing critical steps.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-2302 7.79.80.01952022-07-11
CVE-2024-2172 7.69.80.01712024-03-13
CVE-2024-8954 7.49.80.00852025-03-20
CVE-2026-30831 7.29.80.00332026-03-06
CVE-2026-614666.89.10.00442026-08-06
CVE-2022-40622 6.78.80.00712022-09-13
CVE-2024-12048 6.78.80.00722025-03-20
CVE-2022-1065 6.68.10.02842022-04-19
CVE-2026-44547 6.69.60.00212026-05-12
CVE-2019-16766 6.58.70.01462019-11-29
CVE-2026-673516.58.80.00372026-07-30
CVE-2026-494676.58.80.00412026-08-12
CVE-2024-457646.49.00.00522024-11-08
CVE-2024-9216 6.28.10.00612025-03-20
CVE-2025-24322 6.28.10.00572025-08-20
CVE-2026-559576.27.30.02862026-06-29
CVE-2022-2821 6.17.50.01322022-08-15
CVE-2026-42452 6.08.10.00312026-05-08
CVE-2026-762076.08.10.00272026-08-19
CVE-2024-11302 5.98.00.00232025-03-20
CVE-2023-22833 5.87.60.00412023-06-06
CVE-2024-20153 5.87.50.00322025-01-06
CVE-2023-52424 5.77.40.00722024-05-17
CVE-2026-40542 5.77.30.00462026-04-22
CVE-2025-55138 5.67.40.00312025-08-07