CWE-288— Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.— MITRE CWE catalog
701 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-288page 1 of 15
- CVE-2026-20079CRITICALCVSS 10.0EG 10.0⚠ KEV2026-03-04
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to…
- CVE-2024-1709CRITICALCVSS 10.0EG 10.0⚠ KEV2024-02-21
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
- CVE-2026-19490CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-19
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- CVE-2026-24858CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-27
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 thr…
- CVE-2026-23760CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-22
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a res…
- CVE-2025-57819CRITICALCVSS 9.8EG 9.8⚠ KEV2025-08-28
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary …
- CVE-2025-2747CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-24
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administ…
- CVE-2025-2746CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-24
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control ad…
- CVE-2024-55591CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super…
- CVE-2024-27198CRITICALCVSS 9.8EG 9.8⚠ KEV2024-03-04
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- CVE-2023-46747CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-26
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Softwar…
- CVE-2023-42793CRITICALCVSS 9.8EG 9.8⚠ KEV2023-09-19
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- CVE-2020-10148CRITICALCVSS 9.8EG 9.8⚠ KEV2020-12-29
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may res…
- CVE-2023-20269CRITICALCVSS 9.1EG 9.1⚠ KEV2023-09-06
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an at…
- CVE-2026-18577CRITICALCVSS 8.1EG 9.0⚠ KEV2026-08-02
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
- CVE-2025-24472CRITICALCVSS 8.1EG 9.0⚠ KEV2025-02-11
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior kn…
- CVE-2026-1603CRITICALCVSS 7.5EG 9.0⚠ KEV2026-02-10
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
- CVE-2025-34026CRITICALCVSS 7.5EG 9.0⚠ KEV2025-05-21
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged…
- CVE-2026-18556CRITICALCVSS 7.4EG 9.0⚠ KEV2026-08-01
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
- CVE-2025-4427CRITICALCVSS 5.3EG 9.0⚠ KEV2025-05-13
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
- CVE-2026-33591CRITICALCVSS 10.0EG 10.02026-08-03
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
- CVE-2026-53576CRITICALCVSS 10.0EG 10.02026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endp…
- CVE-2026-53622CRITICALCVSS 10.0EG 10.02026-06-16
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-spec…
- CVE-2026-48491CRITICALCVSS 10.0EG 10.02026-06-16
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced throu…
- CVE-2026-48020CRITICALCVSS 10.0EG 10.02026-06-11
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authenticatio…
- CVE-2024-11639CRITICALCVSS 10.0EG 10.02024-12-10
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
- CVE-2024-10081CRITICALCVSS 10.0EG 10.02024-11-06
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API …
- CVE-2024-2973CRITICALCVSS 10.0EG 10.02024-06-27
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of…
- CVE-2024-2013CRITICALCVSS 10.0EG 10.02024-06-11
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.
- CVE-2023-42770CRITICALCVSS 9.8EG 10.02023-11-21
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the mes…
- CVE-2023-4702CRITICALCVSS 9.8EG 10.02023-09-14
Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.
- CVE-2024-6684CRITICALCVSS 9.9EG 9.92024-08-12
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it …
- CVE-2026-10523CRITICALCVSS 9.8EG 9.92026-06-09
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative ac…
- CVE-2026-104075CRITICALCVSS 9.8EG 9.82026-10-08
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an adm…
- CVE-2026-62101CRITICALCVSS 9.8EG 9.82026-09-17
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
- CVE-2026-27546CRITICALCVSS 9.8EG 9.82026-09-16
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
- CVE-2026-62916CRITICALCVSS 9.8EG 9.82026-09-03
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-76943CRITICALCVSS 9.8EG 9.82026-08-27
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthori…
- CVE-2026-16639CRITICALCVSS 9.8EG 9.82026-08-25
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
- CVE-2026-74001CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
- CVE-2026-75627CRITICALCVSS 9.8EG 9.82026-08-18
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrati…
- CVE-2026-66465CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
- CVE-2026-66453CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
- CVE-2026-24254CRITICALCVSS 9.8EG 9.82026-08-04
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, d…
- CVE-2026-15014CRITICALCVSS 9.8EG 9.82026-07-28
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing…
- CVE-2026-61884CRITICALCVSS 9.8EG 9.82026-07-24
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface w…
- CVE-2026-57807CRITICALCVSS 9.8EG 9.82026-07-10
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO…
- CVE-2019-25763CRITICALCVSS 9.8EG 9.82026-06-20
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST req…
- CVE-2026-49767CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
- CVE-2026-49764CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
Map vulnerabilities like CWE-288 to your infrastructure
EchelonGraph correlates every CVE — across CWE-288 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →