CWE · MITRE source
CWE-304Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.
Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.
Last updated: 20 August 2026 14:15 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 3 mapping(s) from 2 framework(s): STIG rhel 7 2 (mostly) · STIG ubuntu 22 04 1 (mostly)
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 6 hardening rules · 2 OS baselines
V7.2.4
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
IA-8 | Identification and Authentication (Non-organizational Users) | IA | Ensures the authentication process is followed for non-organizational users, avoiding missing critical steps. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2022-2302 UPD | 7.7 | 9.8 | 0.0195 | 2022-07-11 |
CVE-2024-2172 UPD | 7.6 | 9.8 | 0.0171 | 2024-03-13 |
CVE-2024-8954 UPD | 7.4 | 9.8 | 0.0085 | 2025-03-20 |
CVE-2026-30831 UPD | 7.2 | 9.8 | 0.0033 | 2026-03-06 |
CVE-2026-61466 | 6.8 | 9.1 | 0.0044 | 2026-08-06 |
CVE-2022-40622 UPD | 6.7 | 8.8 | 0.0071 | 2022-09-13 |
CVE-2024-12048 UPD | 6.7 | 8.8 | 0.0072 | 2025-03-20 |
CVE-2022-1065 UPD | 6.6 | 8.1 | 0.0284 | 2022-04-19 |
CVE-2026-44547 UPD | 6.6 | 9.6 | 0.0021 | 2026-05-12 |
CVE-2019-16766 UPD | 6.5 | 8.7 | 0.0146 | 2019-11-29 |
CVE-2026-67351 | 6.5 | 8.8 | 0.0037 | 2026-07-30 |
CVE-2026-49467 | 6.5 | 8.8 | 0.0041 | 2026-08-12 |
CVE-2024-45764 | 6.4 | 9.0 | 0.0052 | 2024-11-08 |
CVE-2024-9216 UPD | 6.2 | 8.1 | 0.0061 | 2025-03-20 |
CVE-2025-24322 UPD | 6.2 | 8.1 | 0.0057 | 2025-08-20 |
CVE-2026-55957 | 6.2 | 7.3 | 0.0286 | 2026-06-29 |
CVE-2022-2821 UPD | 6.1 | 7.5 | 0.0132 | 2022-08-15 |
CVE-2026-42452 UPD | 6.0 | 8.1 | 0.0031 | 2026-05-08 |
CVE-2026-76207 | 6.0 | 8.1 | 0.0027 | 2026-08-19 |
CVE-2024-11302 UPD | 5.9 | 8.0 | 0.0023 | 2025-03-20 |
CVE-2023-22833 UPD | 5.8 | 7.6 | 0.0041 | 2023-06-06 |
CVE-2024-20153 UPD | 5.8 | 7.5 | 0.0032 | 2025-01-06 |
CVE-2023-52424 UPD | 5.7 | 7.4 | 0.0072 | 2024-05-17 |
CVE-2026-40542 UPD | 5.7 | 7.3 | 0.0046 | 2026-04-22 |
CVE-2025-55138 UPD | 5.6 | 7.4 | 0.0031 | 2025-08-07 |