Common Weakness Enumeration

    CWE Definition / CWE-308

    CWE-308: Use of Single-factor Authentication

    The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-1390: Weak Authentication

    CWE-654: Reliance on a Single Factor in a Security Decision

    CWE-309: Use of Password System for Primary Authentication