CWE-305— Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.— MITRE CWE catalog
179 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-305page 4 of 4
- CVE-2024-12054MEDIUMCVSS 5.4EG 5.42025-02-13
ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to remotely (proximal/adjacent with RF equipment …
- CVE-2024-20463MEDIUMCVSS 5.4EG 5.42024-10-16
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the configuration or reboot an affected device. This vulnerability…
- CVE-2019-14833MEDIUMCVSS 5.4EG 5.42019-11-06
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller ca…
- CVE-2026-1621MEDIUMCVSS 5.3EG 5.32026-08-14
Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204.
- CVE-2026-35159MEDIUMCVSS 5.3EG 5.32026-07-03
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
- CVE-2026-20152MEDIUMCVSS 5.3EG 5.32026-04-15
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to im…
- CVE-2026-1290MEDIUMCVSS 5.3EG 5.32026-01-21
Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Jamf Pro: from 11.20 through 11.24.
- CVE-2024-42513MEDIUMCVSS 5.3EG 5.32025-02-10
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
- CVE-2023-46611MEDIUMCVSS 5.3EG 5.32025-01-02
Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows Authentication Bypass.This issue affects YOP Poll: from n/a through 6.5.28.
- CVE-2024-39899MEDIUMCVSS 5.3EG 5.32024-07-09
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance with…
- CVE-2023-4939MEDIUMCVSS 5.3EG 5.32023-10-21
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a…
- CVE-2023-4498MEDIUMCVSS 5.3EG 5.32023-09-06
Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only
- CVE-2020-15077MEDIUMCVSS 5.3EG 5.32021-06-04
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further inform…
- CVE-2020-10123MEDIUMCVSS 5.3EG 5.32020-08-21
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components …
- CVE-2026-16895MEDIUMCVSS 5.1EG 5.12026-08-27
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON…
- CVE-2026-33472MEDIUMCVSS 4.8EG 4.82026-04-16
Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The …
- CVE-2024-9683MEDIUMCVSS 4.8EG 4.82024-10-17
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement. While th…
- CVE-2026-59563MEDIUMCVSS 4.6EG 4.62026-09-28
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resour…
- CVE-2025-46750MEDIUMCVSS 4.4EG 4.42025-05-12
SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and change password-protected BIOS settings by importing a BIOS settings file with no password set.
- CVE-2026-16103MEDIUMCVSS 4.3EG 4.32026-07-17
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler…
- CVE-2026-9798MEDIUMCVSS 4.3EG 4.32026-05-28
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiat…
- CVE-2024-4784MEDIUMCVSS 4.2EG 4.22024-08-08
An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.
- CVE-2019-0042MEDIUMCVSS 4.2EG 4.22019-04-10
Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain connected Windows syste…
- CVE-2022-48470MEDIUMCVSS 4.0EG 4.02024-12-28
Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability h…
- CVE-2026-6334LOWCVSS 3.1EG 3.12026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a diff…
- CVE-2025-62772LOWCVSS 3.1EG 3.12025-10-22
On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
- CVE-2025-52996LOWCVSS 3.1EG 3.12025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone,…
- CVE-2025-31703LOWCVSS 2.4EG 2.42026-03-18
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate pri…
- CVE-2025-1880LOWCVSS 2.0EG 2.02025-03-03
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. I…
Map vulnerabilities like CWE-305 to your infrastructure
EchelonGraph correlates every CVE — across CWE-305 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →