What is CWE-305?
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
CWE-305 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.
Source: MITRE CWE (CWE-305 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Bypass Protection Mechanism
Source: MITRE CWE, common consequences.
How CWE-305 is exploited in the wild
Threadlinqs maps 4 CVEs to CWE-305, published between 2024-06-25 and 2026-09-05. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 1 medium. The highest EPSS score in the set is 86.2% (CVE-2025-31161), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-305 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Crushftp (1), N-able (1), Progress Software (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 4 CVEs mapped to CWE-305, CISA KEV first, then by CVSS score.
- CVE-2025-31161 — CISA KEV · CVSS 9.8 critical · EPSS 86.2% · published 2025-04-03
- CVE-2024-37085 — CISA KEV · CVSS 6.8 medium · EPSS 75.6% · published 2024-06-25
- CVE-2026-4670 — CVSS 9.8 critical · EPSS 0.2% · published 2026-04-30
- CVE-2026-86207 — EPSS 0.2% · published 2026-09-05
Affected vendors
Threat activity
7 tracked threats cite CWE-305:
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)HIGH
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active ExploitationCRITICAL
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17CRITICAL
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)HIGH
- Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174)CRITICAL
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)CRITICAL