# CWE-307: Improper Restriction of Excessive Authentication Attempts

> As of 2026-10-05, CWE-307 (Improper Restriction of Excessive Authentication Attempts) underlies 4 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 29 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-307?

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

CWE-307 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/307.html) (CWE-307 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism. An attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.

_Source: MITRE CWE, common consequences._

## How CWE-307 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-307, published between 2026-08-11 and 2026-09-28. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 2 high, 1 medium. The highest EPSS score in the set is 0.4% (CVE-2026-102334), the modelled probability of exploitation in the next 30 days. 29 tracked threats reference CWE-307 directly or through a CVE it covers; the most recent is “Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent” (2026-10-04). Affected products concentrate in siyuan-note (2), NginxProxyManager (1), Quanovate Tech Inc. (operating as Mira / Mira Care) (1).

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-307, CISA KEV first, then by CVSS score.

- [CVE-2026-73046](https://intel.threadlinqs.com/cve/CVE-2026-73046) — CVSS 9.8 critical · EPSS 0.4% · published 2026-08-15
- [CVE-2026-73045](https://intel.threadlinqs.com/cve/CVE-2026-73045) — CVSS 7.5 high · EPSS 0.3% · published 2026-08-15
- [CVE-2026-102334](https://intel.threadlinqs.com/cve/CVE-2026-102334) — CVSS 7.4 high · EPSS 0.4% · published 2026-09-28
- [CVE-2026-66340](https://intel.threadlinqs.com/cve/CVE-2026-66340) — CVSS 5.3 medium · EPSS 0.2% · published 2026-08-11

## Affected vendors

- [siyuan-note](https://intel.threadlinqs.com/vendors/siyuan-note) — 2 CVEs
- **NginxProxyManager** — 1 CVE
- [Quanovate Tech Inc. (operating as Mira / Mira Care)](https://intel.threadlinqs.com/vendors/quanovate-tech-inc-operating-as-mira-mira-care) — 1 CVE

## Threat activity

29 tracked threats cite CWE-307; the 25 most recent are listed.

- [Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent](https://intel.threadlinqs.com/threat/TL-2026-2898) — HIGH · 2026-10-04
- [TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentials](https://intel.threadlinqs.com/threat/TL-2026-2491) — MEDIUM · 2026-09-14
- [OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)](https://intel.threadlinqs.com/threat/TL-2026-2476) — HIGH · 2026-09-13
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — HIGH · 2026-08-16
- [Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data](https://intel.threadlinqs.com/threat/TL-2026-1654) — HIGH · 2026-07-23
- [OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)](https://intel.threadlinqs.com/threat/TL-2026-1321) — HIGH · 2026-07-14
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 & UNK_OutFlareAZ](https://intel.threadlinqs.com/threat/TL-2026-1342) — HIGH · 2026-07-14
- [14 Vulnerabilities Expose Citizen PII in Indian Government Systems — UPSC Portal Admin Takeover, Delhi Directorate of Education & Scholarship Portal Data Exposure](https://intel.threadlinqs.com/threat/TL-2026-1199) — CRITICAL · 2026-07-10
- [Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL · 2026-06-28
- [FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate Firewalls](https://intel.threadlinqs.com/threat/TL-2026-0927) — CRITICAL · 2026-06-24
- [World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design Data](https://intel.threadlinqs.com/threat/TL-2026-0929) — HIGH · 2026-06-24
- [FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways](https://intel.threadlinqs.com/threat/TL-2026-0916) — CRITICAL · 2026-06-23
- [FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool](https://intel.threadlinqs.com/threat/TL-2026-0918) — HIGH · 2026-06-23
- [Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals)](https://intel.threadlinqs.com/threat/TL-2026-0922) — HIGH · 2026-06-23
- [FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols](https://intel.threadlinqs.com/threat/TL-2026-0907) — CRITICAL · 2026-06-22
- [FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways](https://intel.threadlinqs.com/threat/TL-2026-0895) — HIGH · 2026-06-21
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries](https://intel.threadlinqs.com/threat/TL-2026-0882) — HIGH · 2026-06-19
- [Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer](https://intel.threadlinqs.com/threat/TL-2026-1245) — MEDIUM · 2026-06-15
- [FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls Across 194 Countries](https://intel.threadlinqs.com/threat/TL-2026-0868) — CRITICAL · 2026-06-13
- [Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)](https://intel.threadlinqs.com/threat/TL-2026-0775) — HIGH · 2026-06-11
- [P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)](https://intel.threadlinqs.com/threat/TL-2026-0752) — HIGH · 2026-06-10
- [Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan Accounts Exfiltrated (May–June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0705) — HIGH · 2026-06-07
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0610) — HIGH · 2026-05-27
- [WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)](https://intel.threadlinqs.com/threat/TL-2026-0531) — HIGH · 2026-05-19
- [Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0527) — HIGH · 2026-05-18

## Mitigations

- **Architecture and Design**: Common protection mechanisms include: Disconnecting the user after a small number of failed attempts Implementing a timeout Locking out a targeted account Requiring a computational task on the user's part.
- **Architecture and Design / Libraries or Frameworks**: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Dynamic Analysis with Automated Results Interpretation** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Web Application Scanner Web Services Scanner Database Scanners Cost effective for partial coverage: Host-based Vulnerability Scanners - Examine configuration for flaws, verifying that audit mechanisms work, ensure host configuration meets certain predefined criteria
- **Dynamic Analysis with Manual Results Interpretation** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Fuzz Tester Framework-based Fuzzer Cost effective for partial coverage: Forced Path Execution
- **Manual Static Analysis - Source Code** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- **Automated Static Analysis - Source Code** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- **Automated Static Analysis** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Configuration Checker
- **Architecture or Design Review** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-1390 Weak Authentication](https://intel.threadlinqs.com/cwe/CWE-1390)
- [CWE-287 Improper Authentication](https://intel.threadlinqs.com/cwe/CWE-287)
- CWE-799 Improper Control of Interaction Frequency

Canonical: https://intel.threadlinqs.com/cwe/CWE-307
Source definition: https://cwe.mitre.org/data/definitions/307.html
Detection rules and IOCs for threats exploiting CWE-307 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
