CWE-288— Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.— MITRE CWE catalog
683 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-288page 14 of 14
- CVE-2026-73379MEDIUMCVSS 6.5EG 6.52026-08-18
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
- CVE-2026-73381CRITICALCVSS 9.1EG 9.12026-08-18
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
- CVE-2026-73396HIGHCVSS 7.1EG 7.12026-08-18
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
- CVE-2026-73398MEDIUMCVSS 6.5EG 6.52026-08-18
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
- CVE-2026-73399MEDIUMCVSS 6.5EG 6.52026-08-18
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
- CVE-2026-74001CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
- CVE-2026-7458CRITICALCVSS 9.8EG 9.82026-05-02
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_ver…
- CVE-2026-75045CRITICALCVSS 9.1EG 9.12026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
- CVE-2026-75627CRITICALCVSS 9.8EG 9.82026-08-18
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrati…
- CVE-2026-7567CRITICALCVSS 9.8EG 9.82026-05-01
The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 't…
- CVE-2026-76169HIGHCVSS 7.5EG 7.52026-09-04
fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The inte…
- CVE-2026-76943CRITICALCVSS 9.8EG 9.82026-08-27
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthori…
- CVE-2026-77103HIGHCVSS 7.5EG 7.52026-09-08
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- CVE-2026-78259HIGHCVSS 7.3EG 7.32026-08-24
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
- CVE-2026-81168LOWCVSS 3.7EG 3.72026-09-02
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
- CVE-2026-81783HIGHCVSS 7.1EG 7.12026-09-10
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
- CVE-2026-81787MEDIUMCVSS 6.5EG 6.52026-09-10
Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.
- CVE-2026-81796HIGHCVSS 7.3EG 7.32026-09-10
Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
- CVE-2026-81868MEDIUMCVSS 6.5EG 6.52026-09-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCert…
- CVE-2026-81906MEDIUMCVSS 6.3EG 6.32026-09-10
Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete aut…
- CVE-2026-82225HIGHCVSS 7.4EG 7.42026-08-31
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
- CVE-2026-82269HIGHCVSS 8.1EG 8.12026-08-28
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their acco…
- CVE-2026-8321HIGHCVSS 7.3EG 7.32026-05-11
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in auth…
- CVE-2026-8338CRITICALCVSS 9.2EG 9.22026-07-29
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authent…
- CVE-2026-83527HIGHCVSS 8.1EG 8.12026-09-08
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
- CVE-2026-84777HIGHCVSS 7.4EG 7.42026-09-03
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
- CVE-2026-8598CRITICALCVSS 9.1EG 9.12026-05-20
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credenti…
- CVE-2026-86084MEDIUMCVSS 5.5EG 5.52026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise…
- CVE-2026-8697HIGHCVSS 8.8EG 8.82026-05-28
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to …
- CVE-2026-88260HIGHCVSS 8.7EG 8.72026-09-11
Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM …
- CVE-2026-88861HIGHCVSS 8.3EG 8.32026-09-10
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC p…
- CVE-2026-8990MEDIUMCVSS 5.3EG 5.32026-05-28
A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue wa…
- CVE-2026-91143HIGHCVSS 7.2EG 7.22026-09-14
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authe…
Map vulnerabilities like CWE-288 to your infrastructure
EchelonGraph correlates every CVE — across CWE-288 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →