CWE-288— Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.— MITRE CWE catalog
618 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-288page 13 of 13
- CVE-2026-57807CRITICALCVSS 9.8EG 9.82026-07-10
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO…
- CVE-2026-57867HIGHCVSS 8.8EG 8.82026-07-07
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This is…
- CVE-2026-57980MEDIUMCVSS 5.4EG 5.42026-07-17
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
- CVE-2026-58172CRITICALCVSS 9.1EG 9.12026-06-30
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requests. The WebSocket upgrade pipeline br…
- CVE-2026-58517MEDIUMCVSS 4.3EG 4.32026-07-01
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
- CVE-2026-59524MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
- CVE-2026-59545HIGHCVSS 8.1EG 8.12026-07-23
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
- CVE-2026-61425CRITICALCVSS 9.4EG 9.42026-07-20
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
- CVE-2026-61884CRITICALCVSS 9.8EG 9.82026-07-24
The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker…
- CVE-2026-6760CRITICALCVSS 9.8EG 9.82026-04-21
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6768CRITICALCVSS 9.8EG 9.82026-04-21
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6771CRITICALCVSS 9.8EG 9.82026-04-21
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-7458CRITICALCVSS 9.8EG 9.82026-05-02
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_ver…
- CVE-2026-7567CRITICALCVSS 9.8EG 9.82026-05-01
The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 't…
- CVE-2026-8321HIGHCVSS 7.3EG 7.32026-05-11
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in auth…
- CVE-2026-8598CRITICALCVSS 9.1EG 9.12026-05-20
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credenti…
- CVE-2026-8697HIGHCVSS 8.8EG 8.82026-05-28
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to …
- CVE-2026-8990MEDIUMCVSS 5.3EG 5.32026-05-28
A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue wa…
Map vulnerabilities like CWE-288 to your infrastructure
EchelonGraph correlates every CVE — across CWE-288 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →