CWE-305— Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.— MITRE CWE catalog
179 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-305page 2 of 4
- CVE-2026-85500CRITICALCVSS 9.1EG 9.12026-09-17
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.ch…
- CVE-2026-40976CRITICALCVSS 9.1EG 9.12026-04-28
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configurat…
- CVE-2026-40582CRITICALCVSS 9.1EG 9.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow th…
- CVE-2024-49587CRITICALCVSS 9.1EG 9.12025-12-19
Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has bee…
- CVE-2025-68435CRITICALCVSS 9.1EG 9.12025-12-17
Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoint…
- CVE-2025-47776CRITICALCVSS 9.1EG 9.12025-11-04
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentication code in versions 2.27.1 and below.PHP type juggling will cause certain MD5 hashes ma…
- CVE-2024-12802CRITICALCVSS 9.1EG 9.12025-01-09
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to…
- CVE-2023-20154CRITICALCVSS 9.1EG 9.12024-11-15
A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote attacker to access the web interface with administrative privileges. This vulnerability is due to the improper handli…
- CVE-2024-41259CRITICALCVSS 9.1EG 9.12024-08-01
Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.
- CVE-2023-27582CRITICALCVSS 9.1EG 9.12023-03-13
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. In…
- CVE-2021-3850CRITICALCVSS 9.1EG 9.12022-01-25
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
- CVE-2026-10539CRITICALCVSS 9.0EG 9.02026-07-01
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, pote…
- CVE-2024-20674CRITICALCVSS 8.8EG 9.02024-01-09
Windows Kerberos Security Feature Bypass Vulnerability
- CVE-2020-10923CRITICALCVSS 8.8EG 9.02020-07-28
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists with…
- CVE-2026-19292HIGHCVSS 8.8EG 8.82026-08-13
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
- CVE-2026-62427HIGHCVSS 8.8EG 8.82026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore do…
- CVE-2026-41052HIGHCVSS 8.8EG 8.82026-06-29
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
- CVE-2026-3047HIGHCVSS 8.8EG 8.82026-03-05
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establi…
- CVE-2026-0869HIGHCVSS 8.8EG 8.82026-03-03
Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL dat…
- CVE-2024-7557HIGHCVSS 8.8EG 8.82024-08-12
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models with authentication. H…
- CVE-2023-36497HIGHCVSS 8.8EG 8.82023-09-11
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.
- CVE-2022-38700HIGHCVSS 8.8EG 8.82022-09-09
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
- CVE-2021-26726HIGHCVSS 8.8EG 8.82022-02-16
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 20…
- CVE-2025-4994HIGHCVSS 8.7EG 8.72026-06-22
The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configurati…
- CVE-2024-10082HIGHCVSS 8.7EG 8.72024-11-06
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root…
- CVE-2026-2652HIGHCVSS 8.6EG 8.62026-05-15
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI…
- CVE-2022-39245HIGHCVSS 8.4EG 8.42022-09-26
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permission…
- CVE-2026-6266HIGHCVSS 8.3EG 8.32026-05-04
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email owner…
- CVE-2025-54622HIGHCVSS 8.3EG 8.32025-08-06
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2019-14909HIGHCVSS 8.3EG 8.32019-12-04
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
- CVE-2025-31965HIGHCVSS 8.2EG 8.22025-07-29
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.
- CVE-2025-41450HIGHCVSS 8.2EG 8.22025-05-08
Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to version 4.2
- CVE-2023-4898HIGHCVSS 7.5EG 8.22023-09-12
Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
- CVE-2023-2959HIGHCVSS 7.5EG 8.22023-07-17
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.
- CVE-2026-107808HIGHCVSS 8.1EG 8.12026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only acc…
- CVE-2026-33496HIGHCVSS 8.1EG 8.12026-03-26
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to authentication bypass due to cache key confusion. T…
- CVE-2026-32730HIGHCVSS 8.1EG 8.12026-03-18
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomple…
- CVE-2026-22153HIGHCVSS 8.1EG 8.12026-02-10
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote…
- CVE-2025-56224HIGHCVSS 8.1EG 8.12025-10-20
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
- CVE-2024-12776HIGHCVSS 8.1EG 8.12025-03-20
In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete comprom…
- CVE-2024-51738HIGHCVSS 8.1EG 8.12025-01-20
Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated…
- CVE-2024-8642HIGHCVSS 8.1EG 8.12024-09-11
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass…
- CVE-2019-3878HIGHCVSS 8.1EG 8.12019-03-26
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP …
- CVE-2023-28126HIGHCVSS 5.9EG 8.02023-05-09
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
- CVE-2026-41054HIGHCVSS 7.8EG 7.82026-05-20
In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative …
- CVE-2024-10394HIGHCVSS 7.8EG 7.82024-11-14
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credent…
- CVE-2024-20015HIGHCVSS 7.8EG 7.82024-02-05
In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch …
- CVE-2022-23729HIGHCVSS 7.8EG 7.82022-03-04
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
- CVE-2026-86207HIGHCVSS 7.7EG 7.72026-09-05
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
- CVE-2025-53534HIGHCVSS 7.7EG 7.72025-08-05
RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), t…
Map vulnerabilities like CWE-305 to your infrastructure
EchelonGraph correlates every CVE — across CWE-305 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →