CWE-304: Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.
Last updated
Overview
Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.
Real-world CVEs
31 recorded CVEs are caused by CWE-304 (Missing Critical Step in Authentication). The highest-severity and most recent are shown first. 4 new CWE-304 CVEs have been recorded so far in 2026 (12 in 2025).
- CVE-2024-8954
Authentication Bypass in composiohq/composio
Critical · CVSS 9.8 · EPSS 50th2025-03-20 - CVE-2024-2172
Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
Critical · CVSS 9.8 · EPSS 79th2024-03-13 - CVE-2022-2821Critical · CVSS 9.8 · EPSS 53th2022-08-15