CWE-305: Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
152 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-31161 — CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
- CVE-2026-81578 — PaperCut MF/NG: Authentication Bypass
- CVE-2026-25555 — OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
- CVE-2025-24522 — KUNBUS Revolution Pi Authentication Bypass by Primary Weakness
- CVE-2024-36388 — MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
- CVE-2024-1403 — Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
- CVE-2025-46801 — Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerabilit
- CVE-2025-41733 — Possible malfunction credential injection
- CVE-2025-36386 — There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics
- CVE-2025-32011 — KUNBUS Revolution Pi Authentication Bypass by Primary Weakness
- CVE-2025-13915 — Authentication bypass in IBM API Connect
- CVE-2026-28536 — Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnera
- CVE-2026-30849 — MantisBT SOAP API has an authentication bypass vulnerability on MySQL
- CVE-2025-4658 — Authentication Bypass in OPKSSH
- CVE-2025-3757 — Authentication Bypass in OpenPubKey
- CVE-2025-68435 — Zerobyte has Authentication Bypass by Primary Weakness
- CVE-2024-49587 — Glutton V1 endpoints missing authentication
- CVE-2025-47776 — MantisBT: Authentication bypass for some passwords due to PHP type juggling
- CVE-2024-10082 — CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
- CVE-2025-58382 — Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2a
Recently published
- CVE-2026-86207 — Authentication bypass leads to unauthorised access to N-central
- CVE-2026-81578 — PaperCut MF/NG: Authentication Bypass
- CVE-2026-16895 — Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-53561 — Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user
- CVE-2025-14600 — Admin Account Takeover via Path Traversal in vsDesk
- CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
- CVE-2026-1621 — Register Bypass in Universal Sotware's E-Municipality
- CVE-2026-65935 — Bypassing passkey entry in legacy pairing
- CVE-2026-19292 — Bluetooth re-pairing with legitimate device can use lower security level
- CVE-2026-16103 — Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption
- CVE-2026-9597 — Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
- CVE-2026-9571 — Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost
- CVE-2026-35159 — Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attack
- CVE-2026-10539 — Unauthenticated command injection in Control-M/Server communication command
- CVE-2026-41052 — Rancher Privilege Escalation from Project Owner to Host
- CVE-2025-4994 — Authentication Bypass for SafeLine SL6 and SL6+
- CVE-2025-7064 — Freelance Security Lock – Access to Windows OS
- CVE-2026-25555 — OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
- CVE-2026-9798 — Keycloak: keycloak: brute-force protection bypass in ciba flow