CWE-424: Improper Protection of Alternate Path
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
37 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-58136 — Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres
- CVE-2025-48827 — vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
- CVE-2025-48828 — Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
- CVE-2025-68939 — Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via
- CVE-2025-6250 — Privilege Management for Windows - Elevation of Privilege
- CVE-2026-86145 — PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursiv
- CVE-2026-82586 — AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
- CVE-2026-54423 — In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface c
- CVE-2026-4270 — AWS API MCP File Access Restriction Bypass
- CVE-2025-49163 — Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip
- CVE-2025-49162 — Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a
- CVE-2026-0237 — Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
- CVE-2026-66756 — Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
- CVE-2026-58428 — Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2025-58079 — Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker
- CVE-2025-0113 — Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker Containers
- CVE-2026-82754 — ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
- CVE-2025-46655 — CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScri
- CVE-2025-46654 — CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be
- CVE-2026-4913 — Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t
Recently published
- CVE-2026-82586 — AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
- CVE-2026-82754 — ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
- CVE-2026-86145 — PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursiv
- CVE-2026-58428 — Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2026-66756 — Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
- CVE-2026-54423 — In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface c
- CVE-2026-0268 — Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
- CVE-2026-0237 — Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
- CVE-2026-4913 — Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t
- CVE-2026-4270 — AWS API MCP File Access Restriction Bypass
- CVE-2025-68939 — Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via
- CVE-2025-4617 — Prisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma Browser
- CVE-2025-58079 — Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker
- CVE-2025-6250 — Privilege Management for Windows - Elevation of Privilege
- CVE-2025-49163 — Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip
- CVE-2025-49162 — Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a
- CVE-2025-48828 — Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
- CVE-2025-48827 — vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
- CVE-2025-46655 — CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScri
- CVE-2025-46654 — CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be