Threadlinqs IntelligenceStart free

Weakness · BaseCWE-307

CWE-307: Improper Restriction of Excessive Authentication Attempts

Base

As of 2026-10-05, CWE-307 (Improper Restriction of Excessive Authentication Attempts) underlies 4 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 29 tracked threats.

CVEs
4Mapped to CWE-307
CISA KEV
0None listed yet
Critical
1CVSS v3 critical CVEs
Threats
29Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-307?

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

CWE-307 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-307 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism. An attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.

Source: MITRE CWE, common consequences.

How CWE-307 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-307, published between 2026-08-11 and 2026-09-28. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 2 high, 1 medium. The highest EPSS score in the set is 0.4% (CVE-2026-102334), the modelled probability of exploitation in the next 30 days. 29 tracked threats reference CWE-307 directly or through a CVE it covers; the most recent is “Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent” (2026-10-04). Affected products concentrate in siyuan-note (2), NginxProxyManager (1), Quanovate Tech Inc. (operating as Mira / Mira Care) (1).

Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-307, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

29 tracked threats cite CWE-307; the 25 most recent are listed.

Mitigations

  • Architecture and Design: Common protection mechanisms include: Disconnecting the user after a small number of failed attempts Implementing a timeout Locking out a targeted account Requiring a computational task on the user's part.
  • Architecture and Design / Libraries or Frameworks: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Dynamic Analysis with Automated Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Web Application Scanner Web Services Scanner Database Scanners Cost effective for partial coverage: Host-based Vulnerability Scanners - Examine configuration for flaws, verifying that audit mechanisms work, ensure host configuration meets certain predefined criteria
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Fuzz Tester Framework-based Fuzzer Cost effective for partial coverage: Forced Path Execution
  • Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
  • Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
  • Automated Static Analysis (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Configuration Checker
  • Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.