Threadlinqs IntelligenceStart free

Weakness · BaseCWE-305

CWE-305: Authentication Bypass by Primary Weakness

KEV-linkedBase

As of 2026-10-05, CWE-305 (Authentication Bypass by Primary Weakness) underlies 4 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 7 tracked threats.

CVEs
4Mapped to CWE-305
CISA KEV
2Exploited in the wild
Critical
2CVSS v3 critical CVEs
Threats
7Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-305?

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

CWE-305 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.

Source: MITRE CWE (CWE-305 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism

Source: MITRE CWE, common consequences.

How CWE-305 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-305, published between 2024-06-25 and 2026-09-05. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 1 medium. The highest EPSS score in the set is 86.2% (CVE-2025-31161), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-305 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Crushftp (1), N-able (1), Progress Software (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-305, CISA KEV first, then by CVSS score.

  • CVE-2025-31161 — CISA KEV · CVSS 9.8 critical · EPSS 86.2% · published 2025-04-03
  • CVE-2024-37085 — CISA KEV · CVSS 6.8 medium · EPSS 75.6% · published 2024-06-25
  • CVE-2026-4670 — CVSS 9.8 critical · EPSS 0.2% · published 2026-04-30
  • CVE-2026-86207 — EPSS 0.2% · published 2026-09-05

Affected vendors

  • Crushftp — 1 CVE
  • N-able — 1 CVE
  • Progress Software — 1 CVE
  • Vmware — 1 CVE

Threat activity

7 tracked threats cite CWE-305: