CWE-288— Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.— MITRE CWE catalog
683 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-288page 13 of 14
- CVE-2026-49062HIGHCVSS 8.8EG 8.82026-06-15
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.
- CVE-2026-49071MEDIUMCVSS 6.5EG 6.52026-06-17
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
- CVE-2026-49764CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
- CVE-2026-49767CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
- CVE-2026-49887HIGHCVSS 7.8EG 7.82026-09-08
In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2026-50191HIGHCVSS 8.8EG 8.82026-08-18
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Mi…
- CVE-2026-50194HIGHCVSS 8.2EG 8.22026-06-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate…
- CVE-2026-5268CRITICALCVSS 9.1EG 9.12026-07-06
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized ac…
- CVE-2026-53576CRITICALCVSS 10.0EG 10.02026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endp…
- CVE-2026-53622CRITICALCVSS 10.0EG 10.02026-06-16
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-spec…
- CVE-2026-5415HIGHCVSS 8.8EG 8.82026-06-05
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_t…
- CVE-2026-54804HIGHCVSS 7.6EG 7.62026-06-17
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
- CVE-2026-54817MEDIUMCVSS 6.5EG 6.52026-06-17
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.
- CVE-2026-5557MEDIUMCVSS 6.3EG 6.32026-04-05
A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation results in authentication bypass using alte…
- CVE-2026-55666CRITICALCVSS 9.3EG 9.32026-06-24
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/server/loginHandler.ts, handleIdentityToken parses a JWT issued by …
- CVE-2026-56029HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
- CVE-2026-56243HIGHCVSS 8.1EG 8.12026-06-23
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed…
- CVE-2026-57134HIGHCVSS 8.2EG 8.22026-06-18
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth po…
- CVE-2026-57697HIGHCVSS 7.5EG 7.52026-07-13
Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.…
- CVE-2026-57698MEDIUMCVSS 6.5EG 6.52026-07-13
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce…
- CVE-2026-57807CRITICALCVSS 9.8EG 9.82026-07-10
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO…
- CVE-2026-57867HIGHCVSS 8.8EG 8.82026-07-07
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This is…
- CVE-2026-57980MEDIUMCVSS 5.4EG 5.42026-07-17
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
- CVE-2026-58073CRITICALCVSS 9.5EG 9.52026-08-04
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
- CVE-2026-58092HIGHCVSS 8.1EG 8.12026-08-26
In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID…
- CVE-2026-58172CRITICALCVSS 9.1EG 9.12026-06-30
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requests. The WebSocket upgrade pipeline br…
- CVE-2026-58517MEDIUMCVSS 4.3EG 4.32026-07-01
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
- CVE-2026-59524MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
- CVE-2026-59545HIGHCVSS 8.1EG 8.12026-07-23
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
- CVE-2026-61425CRITICALCVSS 9.4EG 9.42026-07-20
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
- CVE-2026-61884CRITICALCVSS 9.8EG 9.82026-07-24
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface w…
- CVE-2026-62101CRITICALCVSS 9.8EG 9.82026-09-17
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
- CVE-2026-62650HIGHCVSS 8.8EG 8.82026-09-08
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be byp…
- CVE-2026-62916CRITICALCVSS 9.8EG 9.82026-09-03
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-63587HIGHCVSS 8.6EG 8.62026-08-25
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive fai…
- CVE-2026-65542HIGHCVSS 8.8EG 8.82026-08-06
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
- CVE-2026-65641CRITICALCVSS 9.3EG 9.32026-08-26
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- CVE-2026-66425MEDIUMCVSS 6.5EG 6.52026-08-06
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
- CVE-2026-66451MEDIUMCVSS 6.5EG 6.52026-08-06
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
- CVE-2026-66453CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
- CVE-2026-66465CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
- CVE-2026-66677HIGHCVSS 7.6EG 7.62026-08-20
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
- CVE-2026-67337MEDIUMCVSS 6.5EG 6.52026-08-01
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verif…
- CVE-2026-6760CRITICALCVSS 9.8EG 9.82026-04-21
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6768CRITICALCVSS 9.8EG 9.82026-04-21
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6771CRITICALCVSS 9.8EG 9.82026-04-21
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-68584HIGHCVSS 8.6EG 8.62026-08-03
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting t…
- CVE-2026-70468HIGHCVSS 8.1EG 8.12026-08-12
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, …
- CVE-2026-71879CRITICALCVSS 9.1EG 9.12026-08-18
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
- CVE-2026-72691HIGHCVSS 7.5EG 7.52026-08-10
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud functio…
Map vulnerabilities like CWE-288 to your infrastructure
EchelonGraph correlates every CVE — across CWE-288 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →