CWE-288— Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.— MITRE CWE catalog
683 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-288page 10 of 14
- CVE-2025-7692HIGHCVSS 8.1EG 8.12025-07-22
The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() function not utilizing a strong enough OTP value, exposing the …
- CVE-2025-7710CRITICALCVSS 9.8EG 9.82025-08-02
The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Face…
- CVE-2025-7742HIGHCVSS 8.3EG 8.32025-07-25
An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile storage. This action may result in remote code execution that …
- CVE-2025-8093HIGHCVSS 8.8EG 8.82025-10-10
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.
- CVE-2025-8359CRITICALCVSS 9.8EG 9.82025-09-06
The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible fo…
- CVE-2025-8995CRITICALCVSS 9.8EG 9.82025-08-15
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.
- CVE-2025-9313CRITICALCVSS 9.3EG 9.32025-10-28
An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This fla…
- CVE-2025-9914HIGHCVSS 7.5EG 7.52025-10-06
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.
- CVE-2025-9967CRITICALCVSS 9.8EG 9.82025-10-15
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updati…
- CVE-2026-0602MEDIUMCVSS 4.3EG 4.32026-03-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge request…
- CVE-2026-0948MEDIUMCVSS 6.5EG 6.52026-02-04
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO Login: from 0.0.0 before 1.0.4.
- CVE-2026-10523CRITICALCVSS 9.8EG 9.92026-06-09
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative ac…
- CVE-2026-12225HIGHCVSS 8.7EG 8.72026-06-16
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sen…
- CVE-2026-1241HIGHCVSS 8.7EG 8.72026-02-26
The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web management interface. The flaw stems from inadequate enforcement of access controls, allowing certain functionality to be acc…
- CVE-2026-12579HIGHCVSS 7.4EG 7.42026-07-01
AS228T with Authentication Bypass Vulnerability
- CVE-2026-12703HIGHCVSS 8.0EG 8.02026-07-29
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish…
- CVE-2026-14917HIGHCVSS 7.7EG 7.72026-09-16
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity fro…
- CVE-2026-15014CRITICALCVSS 9.8EG 9.82026-07-28
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing…
- CVE-2026-1603CRITICALCVSS 7.5EG 9.0⚠ KEV2026-02-10
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
- CVE-2026-1618HIGHCVSS 8.8EG 8.82026-02-13
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation. This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.
- CVE-2026-16198MEDIUMCVSS 5.6EG 5.62026-07-18
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allow…
- CVE-2026-16639CRITICALCVSS 9.8EG 9.82026-08-25
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
- CVE-2026-16647MEDIUMCVSS 4.1EG 4.12026-09-02
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
- CVE-2026-1747MEDIUMCVSS 4.3EG 4.32026-02-25
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to…
- CVE-2026-1779HIGHCVSS 8.1EG 8.12026-02-26
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for u…
- CVE-2026-18047MEDIUMCVSS 6.5EG 6.52026-07-28
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass…
- CVE-2026-18556CRITICALCVSS 7.4EG 9.0⚠ KEV2026-08-01
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
- CVE-2026-18574CRITICALCVSS 9.3EG 9.32026-08-03
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitra…
- CVE-2026-18577CRITICALCVSS 8.1EG 9.0⚠ KEV2026-08-02
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
- CVE-2026-18636MEDIUMCVSS 6.8EG 6.82026-08-11
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefi…
- CVE-2026-1917HIGHCVSS 4.3EG 7.32026-03-25
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.
- CVE-2026-19490CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-19
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- CVE-2026-20079CRITICALCVSS 10.0EG 10.0⚠ KEV2026-03-04
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to…
- CVE-2026-20459MEDIUMCVSS 5.3EG 5.32026-07-01
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges nee…
- CVE-2026-20460MEDIUMCVSS 5.3EG 5.32026-07-01
In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution…
- CVE-2026-2095CRITICALCVSS 9.8EG 9.82026-02-10
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.
- CVE-2026-2096CRITICALCVSS 9.8EG 9.82026-02-10
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.
- CVE-2026-21411HIGHCVSS 8.8EG 8.82026-01-06
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.
- CVE-2026-22037HIGHCVSS 8.4EG 8.42026-01-19
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be bypassed using URL-encoded ch…
- CVE-2026-22049HIGHCVSS 8.8EG 8.82026-07-22
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials…
- CVE-2026-22205HIGHCVSS 7.5EG 7.52026-02-26
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication …
- CVE-2026-22341MEDIUMCVSS 6.7EG 6.72026-02-20
Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authentication Abuse.This issue affects Booked: from n/a through <= 3.0.0.
- CVE-2026-22572HIGHCVSS 7.2EG 7.22026-03-10
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager …
- CVE-2026-22731HIGHCVSS 8.1EG 8.12026-03-19
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additio…
- CVE-2026-22733HIGHCVSS 8.1EG 8.12026-03-20
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This is…
- CVE-2026-23480HIGHCVSS 8.8EG 8.82026-03-23
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability. The upsertUser endpoint has 3 issues: it is missing superAdminAuthMiddleware, any logged-in user can call it; the orig…
- CVE-2026-23595HIGHCVSS 8.8EG 8.82026-02-17
An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an atta…
- CVE-2026-23596MEDIUMCVSS 6.5EG 6.52026-02-17
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system avai…
- CVE-2026-23760CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-22
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a res…
- CVE-2026-24185HIGHCVSS 7.1EG 7.12026-08-18
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If bes…
Map vulnerabilities like CWE-288 to your infrastructure
EchelonGraph correlates every CVE — across CWE-288 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →