CWE-288— Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.— MITRE CWE catalog
617 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-288page 12 of 13
- CVE-2026-40780HIGHCVSS 7.5EG 7.52026-06-02
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1.
- CVE-2026-40781HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
- CVE-2026-40785HIGHCVSS 7.1EG 7.12026-06-15
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
- CVE-2026-40790MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
- CVE-2026-40799MEDIUMCVSS 5.8EG 5.82026-06-15
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
- CVE-2026-41059HIGHCVSS 8.2EG 8.22026-04-22
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `s…
- CVE-2026-41308MEDIUMCVSS 6.5EG 6.52026-05-08
Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a gene…
- CVE-2026-42300CRITICALCVSS 9.3EG 9.32026-05-12
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated userID when…
- CVE-2026-42303MEDIUMCVSS 6.1EG 6.12026-05-12
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an admini…
- CVE-2026-42378MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
- CVE-2026-42411HIGHCVSS 8.1EG 8.12026-06-15
Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
- CVE-2026-42629HIGHCVSS 8.8EG 8.82026-06-17
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
- CVE-2026-42654HIGHCVSS 7.1EG 7.12026-06-02
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.
- CVE-2026-42668HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
- CVE-2026-42735HIGHCVSS 8.2EG 8.22026-05-27
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.
- CVE-2026-42745HIGHCVSS 7.3EG 7.32026-05-27
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.
- CVE-2026-42749HIGHCVSS 7.1EG 7.12026-05-27
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post …
- CVE-2026-42760HIGHCVSS 7.5EG 7.52026-05-27
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/…
- CVE-2026-4320CRITICALCVSS 9.3EG 9.32026-05-18
Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running…
- CVE-2026-43945HIGHCVSS 8.9EG 8.92026-05-26
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform…
- CVE-2026-44574HIGHCVSS 8.1EG 8.12026-05-13
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployme…
- CVE-2026-44575HIGHCVSS 7.5EG 7.52026-05-13
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through …
- CVE-2026-45109HIGHCVSS 7.5EG 7.52026-05-13
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed…
- CVE-2026-45217MEDIUMCVSS 6.5EG 6.52026-05-25
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through …
- CVE-2026-4524MEDIUMCVSS 6.5EG 6.52026-05-14
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public pr…
- CVE-2026-45577MEDIUMCVSS 6.9EG 6.92026-05-18
Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In…
- CVE-2026-4700CRITICALCVSS 9.8EG 9.82026-03-24
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- CVE-2026-47200MEDIUMCVSS 5.3EG 5.32026-05-29
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experim…
- CVE-2026-47481MEDIUMCVSS 6.5EG 6.52026-07-14
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalat…
- CVE-2026-48020CRITICALCVSS 10.0EG 10.02026-06-11
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authenticatio…
- CVE-2026-48491CRITICALCVSS 10.0EG 10.02026-06-16
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced throu…
- CVE-2026-48970HIGHCVSS 8.1EG 8.12026-06-15
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
- CVE-2026-49062HIGHCVSS 8.8EG 8.82026-06-15
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.
- CVE-2026-49071MEDIUMCVSS 6.5EG 6.52026-06-17
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
- CVE-2026-49764CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
- CVE-2026-49767CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
- CVE-2026-50194HIGHCVSS 8.2EG 8.22026-06-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate…
- CVE-2026-5268CRITICALCVSS 9.1EG 9.12026-07-06
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized ac…
- CVE-2026-53576CRITICALCVSS 10.0EG 10.02026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endp…
- CVE-2026-53622CRITICALCVSS 10.0EG 10.02026-06-16
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. Wh…
- CVE-2026-5415HIGHCVSS 8.8EG 8.82026-06-05
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_t…
- CVE-2026-54804HIGHCVSS 7.6EG 7.62026-06-17
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
- CVE-2026-54817MEDIUMCVSS 6.5EG 6.52026-06-17
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.
- CVE-2026-5557MEDIUMCVSS 6.3EG 6.32026-04-05
A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation results in authentication bypass using alte…
- CVE-2026-55666CRITICALCVSS 9.3EG 9.32026-06-24
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/server/loginHandler.ts, handleIdentityToken parses a JWT issued by …
- CVE-2026-56029HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
- CVE-2026-56243HIGHCVSS 8.1EG 8.12026-06-23
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed…
- CVE-2026-57697HIGHCVSS 7.5EG 7.52026-07-13
Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.…
- CVE-2026-57698MEDIUMCVSS 6.5EG 6.52026-07-13
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce…
- CVE-2026-57807CRITICALCVSS 9.8EG 9.82026-07-10
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO…
Map vulnerabilities like CWE-288 to your infrastructure
EchelonGraph correlates every CVE — across CWE-288 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →