CWE-288: Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
576 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-23760 — SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
- CVE-2025-34026 — Versa Concerto Actuator Authentication Bypass Information Leak
- CVE-2025-2746 — Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
- CVE-2024-27198 — In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- CVE-2024-9989 — Crypto <= 2.18 - Authentication Bypass via log_in
- CVE-2026-1603 — An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to
- CVE-2024-10081 — CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
- CVE-2025-4427 — Authentication Bypass
- CVE-2024-23917 — In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
- CVE-2026-20079 — Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
- CVE-2024-33610 — "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log
- CVE-2024-49328 — WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
- CVE-2026-24858 — An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnaly
- CVE-2024-9933 — WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
- CVE-2024-10245 — Relais 2FA <= 1.0 - Authentication Bypass
- CVE-2025-0674 — Elber Communications Equipment Authentication Bypass Using an Alternate Path or Channel
- CVE-2025-34143 — ETQ Reliance CG Authentication Bypass via Trailing Space RCE
- CVE-2025-24472 — An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.
- CVE-2026-18577 — Incomplete patch leads to administrative account takeover
- CVE-2026-18556 — Unauthenticated administrative account takeover
Recently published
- CVE-2026-86084 — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
- CVE-2026-83527 — An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated att
- CVE-2026-62650 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web
- CVE-2026-76169 — fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
- CVE-2026-84777 — WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability
- CVE-2026-16647 — Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
- CVE-2026-81168 — CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105
- CVE-2026-82225 — WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerability
- CVE-2026-82269 — Gophish Account Lockout and Forced Password Change Bypassable via API Key
- CVE-2026-76943 — Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel
- CVE-2026-65641 — A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- CVE-2026-3035 — Authentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2026-58092 — Unauthorized credential switching
- CVE-2026-16639 — Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081
- CVE-2026-63587 — SMS Password Authorization Bypass via Failed Attempt Counter
- CVE-2026-78259 — WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability
- CVE-2026-74001 — WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability
- CVE-2026-66677 — WordPress Leyka plugin <= 3.32.3 - Broken Authentication vulnerability
- CVE-2026-50191 — 4gaBoards: Pre-Account Takeover via SSO Email Linkage
- CVE-2026-24185 — NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while