CWE-307

Improper Restriction of Excessive Authentication Attempts

Parent: CWE-1390 - Weak Authentication

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

607 vulnerabilities with CWE-307
CVE-2026-15144 HIGH
@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation
CVSS 7.3
CVE-2026-16347 HIGH
Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
CVSS 8.8
CVE-2026-55977 LOW
ESharePro - Bypass of Application Rate-Limiting Mechanism
CVSS 3.3
CVE-2026-65894 HIGH
CP PLUS EZ-P21 IP Camera <= v4.8.8.1 - Brute-Force Snapshot Access
CVE-2026-8285 MEDIUM
OTP Bypass in Universal Sotware's FlexCity
CVSS 4.3
CVE-2026-32825 HIGH
dataCycle No Brute-Force Protection On Web And API Login Endpoints
CVSS 7.3
CVE-2026-62220 MEDIUM
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
CVSS 5.3
CVE-2026-44596 MEDIUM
YAMCS yamcs-core 5.12.7 - No Rate Limiting
CVSS 6.5
CVE-2026-14254 HIGH
Improper Restriction of Excessive Authentication Attempts in Delphix Continuous Data
CVE-2026-61458 HIGH
PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint
CVSS 7.5
CVE-2026-42952 HIGH
Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts
CVSS 7.5
CVE-2026-11915 MEDIUM
Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047
CVSS 5.9
CVE-2026-15079 MEDIUM
Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070
CVSS 5.4
CVE-2026-55501 HIGH
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVSS 7.3
CVE-2026-53904 HIGH
Mycomplianceoffice Mco < 25.3.3.1 - Denial of Service
CVSS 7.1
CVE-2026-35098 MEDIUM
Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
CVE-2026-11779 MEDIUM
PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
CVE-2026-50176 HIGH
EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts
CVSS 7.5
CVE-2026-47380 MEDIUM
NocoDB: User Enumeration via Sign-In Timing
CVE-2026-56234 MEDIUM
Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint
CVSS 5.3
CVE-2026-56450 MEDIUM
AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication Codes
CVE-2026-47203 LOW
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
CVE-2026-6853 CRITICAL
OTP Bypass in Başbelen Group's Pause+ Mobile App
CVSS 9.8
CVE-2026-3329 HIGH
Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts
CVSS 7.5
CVE-2026-43926 MEDIUM
FOSSBilling's password reset confirmation endpoint lacks rate limiting
Details
Vulnerabilities 607