CWE-307 - Improper Restriction of Excessive Authentication Attempts - Cwe

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
August 17, 2026
Last Seen
August 17, 2026

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-73046 - SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth Latest Vulnerabilities / 1d CVE ID : CVE-2026-73046 Published : Aug. 15, 2026, 10:16 p.m. 6 hours, 18 minutes ago Description : SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consult — cvefeed.io · August 17, 2026

CVSS v3.1 Breakdown