CWE-307: Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Last updated
Overview
CWE-307 (Improper Restriction of Excessive Authentication Attempts) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
389 recorded CVEs are caused by CWE-307 (Improper Restriction of Excessive Authentication Attempts). The highest-severity and most recent are shown first. 82 new CWE-307 CVEs have been recorded so far in 2026 (94 in 2025).
- CVE-2026-6853
OTP Bypass in Başbelen Group's Pause+ Mobile App
Critical · CVSS 9.8 · EPSS 26th2026-06-12 - CVE-2026-8760
Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force
Critical · CVSS 9.8 · EPSS 44th2026-05-27 - CVE-2020-37228
iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass