Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-308
Weakness type CWE-308 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 8 | 8 | 0 |
Monthly trend
█▃▃█▁
2026-06 3 · 2026-07 1 · 2026-08 1 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-67611 | 8.6 | 54.6 | — | OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration |
| CVE-2026-56022 | 6.9 | 44.4 | — | Webmin MFA bypass |
| CVE-2026-15616 | 9.1 | 42.7 | — | Local MFA not enforced during SSO sign-in |
| CVE-2026-58240 | 9.8 | 42.7 | — | Missing Authentication check in SAP NetWeaver (Message Server) |
| CVE-2026-85590 | 7.1 | 42.0 | — | phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable |
| CVE-2026-45749 | 8.1 | 38.0 | — | Termix's TOTP two-factor authentication can be disabled or bypassed using only the acco… |
| CVE-2026-79763 | 5.3 | 22.2 | — | Termix: MFA-critical operations accept the account password as a sole factor (regressio… |
| CVE-2024-27928 | 5.9 | 18.4 | — | Vantage6: 2FA can be circumvented with hacked email access |