# CWE-305: Authentication Bypass by Primary Weakness

**KEV-linked**

> As of 2026-10-05, CWE-305 (Authentication Bypass by Primary Weakness) underlies 4 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 7 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-305?

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

CWE-305 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/305.html) (CWE-305 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism

_Source: MITRE CWE, common consequences._

## How CWE-305 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-305, published between 2024-06-25 and 2026-09-05. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 2 critical, 1 medium. The highest EPSS score in the set is 86.2% (CVE-2025-31161), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-305 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Crushftp (1), N-able (1), Progress Software (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-305, CISA KEV first, then by CVSS score.

- [CVE-2025-31161](https://intel.threadlinqs.com/cve/CVE-2025-31161) — CISA KEV · CVSS 9.8 critical · EPSS 86.2% · published 2025-04-03
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085) — CISA KEV · CVSS 6.8 medium · EPSS 75.6% · published 2024-06-25
- [CVE-2026-4670](https://intel.threadlinqs.com/cve/CVE-2026-4670) — CVSS 9.8 critical · EPSS 0.2% · published 2026-04-30
- [CVE-2026-86207](https://intel.threadlinqs.com/cve/CVE-2026-86207) — EPSS 0.2% · published 2026-09-05

## Affected vendors

- **Crushftp** — 1 CVE
- [N-able](https://intel.threadlinqs.com/vendors/n-able) — 1 CVE
- **Progress Software** — 1 CVE
- [Vmware](https://intel.threadlinqs.com/vendors/vmware) — 1 CVE

## Threat activity

7 tracked threats cite CWE-305:

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH · 2026-10-03
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — CRITICAL · 2026-08-28
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH · 2026-07-14
- [phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17](https://intel.threadlinqs.com/threat/TL-2026-0789) — CRITICAL · 2026-06-14
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0610) — HIGH · 2026-05-27
- [Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174)](https://intel.threadlinqs.com/threat/TL-2026-0452) — CRITICAL · 2026-05-04
- [Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)](https://intel.threadlinqs.com/threat/TL-2026-0326) — CRITICAL · 2026-04-06

## Related weaknesses

- [CWE-1390 Weak Authentication](https://intel.threadlinqs.com/cwe/CWE-1390)

Canonical: https://intel.threadlinqs.com/cwe/CWE-305
Source definition: https://cwe.mitre.org/data/definitions/305.html
Detection rules and IOCs for threats exploiting CWE-305 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
