Common Weakness Enumeration

    CWE Definition / CWE-304

    CWE-304: Missing Critical Step in Authentication

    The product implements an authentication technique, but it skips a step that weakens the technique.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-303: Incorrect Implementation of Authentication Algorithm

    CWE-573: Improper Following of Specification by Caller