Threadlinqs IntelligenceStart free

Weakness · BaseCWE-294

CWE-294: Authentication Bypass by Capture-replay

Likelihood of exploit: HighKEV-linkedBase

As of 2026-10-05, CWE-294 (Authentication Bypass by Capture-replay) underlies 7 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 43 tracked threats. MITRE rates its likelihood of exploit as High.

CVEs
7Mapped to CWE-294
CISA KEV
1Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
43Tracked campaigns citing it
Likelihood
HighMITRE likelihood of exploit

Last updated:

What is CWE-294?

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

CWE-294 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-294 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Gain Privileges or Assume Identity. Messages sent with a capture-relay attack allow access to resources which are not otherwise accessible without proper authentication.

Source: MITRE CWE, common consequences.

How CWE-294 is exploited in the wild

Threadlinqs maps 7 CVEs to CWE-294, published between 2023-03-14 and 2026-09-08. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 2 high, 2 medium. The highest EPSS score in the set is 93.3% (CVE-2023-23397), the modelled probability of exploitation in the next 30 days. 43 tracked threats reference CWE-294 directly or through a CVE it covers; the most recent is “September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs” (2026-09-08). Affected products concentrate in CoreWCF (2), Microsoft (1), Spring (1), among 5 vendors in total.

Vulnerabilities (CVEs)

All 7 CVEs mapped to CWE-294, CISA KEV first, then by CVSS score.

Affected vendors

  • CoreWCF — 2 CVEs
  • Microsoft — 1 CVE
  • Spring — 1 CVE
  • jeremyevans — 1 CVE
  • macropay-solutions — 1 CVE

Threat activity

43 tracked threats cite CWE-294; the 25 most recent are listed.

Mitigations

  • Architecture and Design: Utilize some sequence or time stamping functionality along with a checksum which takes this into account in order to ensure that messages can be parsed only once.
  • Architecture and Design: Since any attacker who can listen to traffic can see sequence numbers, it is necessary to sign messages with some kind of cryptography to ensure that sequence numbers are not simply doctored along with content.

Source: MITRE CWE, potential mitigations.