CWE-305— Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.— MITRE CWE catalog
179 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-305page 3 of 4
- CVE-2023-6998HIGHCVSS 7.7EG 7.72023-12-30
Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.
- CVE-2026-65935HIGHCVSS 7.6EG 7.62026-08-13
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below.
- CVE-2026-9047HIGHCVSS 7.6EG 7.62026-05-26
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconf…
- CVE-2020-10126HIGHCVSS 7.6EG 7.62020-08-21
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer and execute arbitrar…
- CVE-2026-8932HIGHCVSS 7.5EG 7.52026-07-03
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to r…
- CVE-2025-51663HIGHCVSS 7.5EG 7.52025-11-19
A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by faking X-Real-IP and X-Forwarded-For HTTP headers. This can en…
- CVE-2023-4727HIGHCVSS 7.5EG 7.52024-06-11
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP …
- CVE-2024-20378HIGHCVSS 7.5EG 7.52024-05-01
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to a lack of authent…
- CVE-2021-43175HIGHCVSS 7.5EG 7.52021-12-07
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOaut…
- CVE-2020-15078HIGHCVSS 7.5EG 7.52021-04-26
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
- CVE-2021-21403HIGHCVSS 7.5EG 7.52021-03-26
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.
- CVE-2023-27535HIGHCVSS 5.9EG 7.52023-03-30
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool f…
- CVE-2026-53561HIGHCVSS 7.4EG 7.42026-08-25
An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an una…
- CVE-2021-3547HIGHCVSS 7.4EG 7.42021-07-12
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client c…
- CVE-2025-56132HIGHCVSS 7.3EG 7.32025-09-30
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to d…
- CVE-2024-6637HIGHCVSS 7.3EG 7.32024-07-20
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it…
- CVE-2024-34077HIGHCVSS 7.3EG 7.32024-05-14
MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an …
- CVE-2020-14359HIGHCVSS 7.3EG 7.32021-02-23
A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means the…
- CVE-2025-58382HIGHCVSS 7.2EG 7.22026-02-03
A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary comma…
- CVE-2022-4722HIGHCVSS 7.2EG 7.22022-12-27
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2026-33892HIGHCVSS 7.1EG 7.12026-04-14
A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 <…
- CVE-2024-12582HIGHCVSS 7.1EG 7.12024-12-24
A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a user sets up across a hybrid multi-cloud environment. When the default authenticati…
- CVE-2025-53167MEDIUMCVSS 6.9EG 6.92025-07-07
Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-27371MEDIUMCVSS 6.9EG 6.92025-03-03
In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to authorization servers. The affected RFCs …
- CVE-2025-27370MEDIUMCVSS 6.9EG 6.92025-03-03
OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server could trick a Client into writing attacker-controlled…
- CVE-2025-31192MEDIUMCVSS 6.7EG 6.72025-03-31
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.
- CVE-2024-38433MEDIUMCVSS 6.7EG 6.72024-07-11
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by …
- CVE-2025-7064MEDIUMCVSS 6.6EG 6.62026-06-11
Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
- CVE-2025-68609MEDIUMCVSS 6.6EG 6.62026-01-22
A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks bei…
- CVE-2026-88837MEDIUMCVSS 6.5EG 6.52026-09-23
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
- CVE-2026-9571MEDIUMCVSS 6.5EG 6.52026-07-13
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to ob…
- CVE-2026-5545MEDIUMCVSS 6.5EG 6.52026-05-13
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subse…
- CVE-2026-40039MEDIUMCVSS 6.5EG 6.52026-04-13
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to val…
- CVE-2026-3784MEDIUMCVSS 6.5EG 6.52026-03-11
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.
- CVE-2026-1965MEDIUMCVSS 6.5EG 6.52026-03-11
libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to …
- CVE-2025-59980MEDIUMCVSS 6.5EG 6.52025-10-09
An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a us…
- CVE-2025-59941MEDIUMCVSS 6.5EG 6.52025-09-29
go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.8 and below, go-f3's justification verification caching mechanism has a vulnerability where verification results are cached without properly considering t…
- CVE-2024-5956MEDIUMCVSS 6.5EG 6.52024-09-05
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
- CVE-2022-40723MEDIUMCVSS 6.5EG 6.52023-04-25
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
- CVE-2022-0451MEDIUMCVSS 6.5EG 6.52022-02-18
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirectio…
- CVE-2024-5957MEDIUMCVSS 6.3EG 6.32024-09-05
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
- CVE-2022-38081MEDIUMCVSS 6.2EG 6.22022-09-09
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
- CVE-2022-38064MEDIUMCVSS 6.2EG 6.22022-09-09
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
- CVE-2025-23017MEDIUMCVSS 6.0EG 6.02025-02-24
WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.
- CVE-2022-3100MEDIUMCVSS 5.9EG 5.92023-01-18
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
- CVE-2023-27538MEDIUMCVSS 5.5EG 5.52023-03-30
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool …
- CVE-2026-1713MEDIUMCVSS 5.0EG 5.52026-03-03
IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD
- CVE-2026-9597MEDIUMCVSS 5.4EG 5.42026-07-13
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional s…
- CVE-2026-3591MEDIUMCVSS 5.4EG 5.42026-03-25
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default…
- CVE-2025-30428MEDIUMCVSS 5.4EG 5.42025-03-31
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.
Map vulnerabilities like CWE-305 to your infrastructure
EchelonGraph correlates every CVE — across CWE-305 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →