CWE•Base•Draft•20 recent CVEs
CWE-307Improper Restriction of Excessive Authentication Attempts
Description
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Common consequences
- Access Control→Bypass Protection MechanismAn attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.
Potential mitigations
- Architecture and Design[object Object]
- Architecture and Design[object Object]
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-891747.52026-09-11CVE-2026-887706.52026-09-10CVE-2026-784907.52026-09-09CVE-2026-867297.42026-09-08CVE-2026-62239.42026-09-07CVE-2026-205144.42026-09-07CVE-2026-205126.72026-09-07CVE-2026-861866.52026-09-05CVE-2026-852378.12026-09-03CVE-2026-166752026-09-01CVE-2026-133482026-09-01CVE-2026-826447.52026-08-30CVE-2026-826436.52026-08-30CVE-2026-786172026-08-28CVE-2026-769407.52026-08-28CVE-2026-182605.72026-08-25CVE-2026-786559.12026-08-25CVE-2026-628622026-08-25CVE-2026-755755.32026-08-25CVE-2026-785512026-08-24