# CWE-294: Authentication Bypass by Capture-replay

**Likelihood of exploit:** High · **KEV-linked**

> As of 2026-10-05, CWE-294 (Authentication Bypass by Capture-replay) underlies 7 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 43 tracked threats. MITRE rates its likelihood of exploit as High.

**Last updated:** 2026-10-05

## What is CWE-294?

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

CWE-294 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/294.html) (CWE-294 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Gain Privileges or Assume Identity. Messages sent with a capture-relay attack allow access to resources which are not otherwise accessible without proper authentication.

_Source: MITRE CWE, common consequences._

## How CWE-294 is exploited in the wild

Threadlinqs maps 7 CVEs to CWE-294, published between 2023-03-14 and 2026-09-08. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 2 high, 2 medium. The highest EPSS score in the set is 93.3% (CVE-2023-23397), the modelled probability of exploitation in the next 30 days. 43 tracked threats reference CWE-294 directly or through a CVE it covers; the most recent is “September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs” (2026-09-08). Affected products concentrate in CoreWCF (2), Microsoft (1), Spring (1), among 5 vendors in total.

## Vulnerabilities (CVEs)

All 7 CVEs mapped to CWE-294, CISA KEV first, then by CVSS score.

- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397) — CISA KEV · CVSS 9.8 critical · EPSS 93.3% · published 2023-03-14
- [CVE-2026-54783](https://intel.threadlinqs.com/cve/CVE-2026-54783) — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-41707](https://intel.threadlinqs.com/cve/CVE-2026-41707) — CVSS 7.4 high · published 2026-08-25
- [CVE-2026-54779](https://intel.threadlinqs.com/cve/CVE-2026-54779) — CVSS 5.9 medium · EPSS 0.2% · published 2026-07-08
- [CVE-2026-82470](https://intel.threadlinqs.com/cve/CVE-2026-82470) — CVSS 5.4 medium · published 2026-08-29
- [CVE-2026-55250](https://intel.threadlinqs.com/cve/CVE-2026-55250) — EPSS 0.5% · published 2026-09-08
- [CVE-2026-86219](https://intel.threadlinqs.com/cve/CVE-2026-86219) — EPSS 0.2% · published 2026-09-06

## Affected vendors

- [CoreWCF](https://intel.threadlinqs.com/vendors/corewcf) — 2 CVEs
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- **Spring** — 1 CVE
- **jeremyevans** — 1 CVE
- **macropay-solutions** — 1 CVE

## Threat activity

43 tracked threats cite CWE-294; the 25 most recent are listed.

- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs](https://intel.threadlinqs.com/threat/TL-2026-2398) — CRITICAL · 2026-09-08
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL · 2026-09-08
- [Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login Sessions](https://intel.threadlinqs.com/threat/TL-2026-2253) — MEDIUM · 2026-08-31
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain Usage](https://intel.threadlinqs.com/threat/TL-2026-2255) — MEDIUM · 2026-08-31
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate Ratings](https://intel.threadlinqs.com/threat/TL-2026-2159) — CRITICAL · 2026-08-26
- [Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows](https://intel.threadlinqs.com/threat/TL-2026-2140) — HIGH · 2026-08-25
- [91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285](https://intel.threadlinqs.com/threat/TL-2026-2105) — CRITICAL · 2026-08-21
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain](https://intel.threadlinqs.com/threat/TL-2026-2031) — HIGH · 2026-08-16
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)](https://intel.threadlinqs.com/threat/TL-2026-1987) — CRITICAL · 2026-08-11
- [WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures](https://intel.threadlinqs.com/threat/TL-2026-1966) — HIGH · 2026-08-10
- [UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion](https://intel.threadlinqs.com/threat/TL-2026-1962) — HIGH · 2026-08-09
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — HIGH · 2026-07-29
- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://intel.threadlinqs.com/threat/TL-2026-1699) — HIGH · 2026-07-25
- [KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization](https://intel.threadlinqs.com/threat/TL-2026-1701) — HIGH · 2026-07-25
- [German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft](https://intel.threadlinqs.com/threat/TL-2026-1602) — HIGH · 2026-07-22
- [German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA](https://intel.threadlinqs.com/threat/TL-2026-1612) — HIGH · 2026-07-22
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — HIGH · 2026-07-22
- [EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security Firms](https://intel.threadlinqs.com/threat/TL-2026-1201) — HIGH · 2026-07-11
- [Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions](https://intel.threadlinqs.com/threat/TL-2026-1202) — HIGH · 2026-07-11
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)](https://intel.threadlinqs.com/threat/TL-2026-1036) — HIGH · 2026-07-01
- [LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)](https://intel.threadlinqs.com/threat/TL-2026-0926) — MEDIUM · 2026-06-24
- [CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account Takeover (Storm-1167 Overlap)](https://intel.threadlinqs.com/threat/TL-2026-0913) — HIGH · 2026-06-23
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing Against Microsoft 365](https://intel.threadlinqs.com/threat/TL-2026-0888) — HIGH · 2026-06-20
- [Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public Sector](https://intel.threadlinqs.com/threat/TL-2026-0878) — HIGH · 2026-06-19
- [Roblox Developer Group Takeovers via Malicious 'robase' Python Package and Discord Job-Offer Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-0851) — HIGH · 2026-06-18

## Mitigations

- **Architecture and Design**: Utilize some sequence or time stamping functionality along with a checksum which takes this into account in order to ensure that messages can be parsed only once.
- **Architecture and Design**: Since any attacker who can listen to traffic can see sequence numbers, it is necessary to sign messages with some kind of cryptography to ensure that sequence numbers are not simply doctored along with content.

_Source: MITRE CWE, potential mitigations._

## Related weaknesses

- [CWE-1390 Weak Authentication](https://intel.threadlinqs.com/cwe/CWE-1390)
- [CWE-287 Improper Authentication](https://intel.threadlinqs.com/cwe/CWE-287)

Canonical: https://intel.threadlinqs.com/cwe/CWE-294
Source definition: https://cwe.mitre.org/data/definitions/294.html
Detection rules and IOCs for threats exploiting CWE-294 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
