VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 2 of 32
  • CVE-2022-25369CriJan 23, 2026
    risk 0.67cvss 9.8epss 0.41

    An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new…

  • CVE-2025-34026HigKEVMay 21, 2025
    risk 0.67cvss 7.5epss 0.83

    The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace…

  • CVE-2024-50477CriOct 28, 2024
    risk 0.67cvss 9.8epss 0.08

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

  • CVE-2023-2986CriJun 8, 2023
    risk 0.67cvss 9.8epss 0.43

    The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows…

  • CVE-2024-10924CriNov 15, 2024
    risk 0.66cvss 9.8epss 0.82

    The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user'…

  • CVE-2024-11639CriDec 10, 2024
    risk 0.65cvss 10.0epss 0.05

    An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

  • CVE-2024-2973CriJun 27, 2024
    risk 0.65cvss 10.0epss 0.01

    An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device. Only routers or conductors…

  • CVE-2024-2013CriJun 11, 2024
    risk 0.65cvss 10.0epss 0.01

    An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

  • CVE-2024-2056CriMar 5, 2024
    risk 0.65cvss 9.8epss 0.17

    Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security…

  • CVE-2023-42770CriNov 21, 2023
    risk 0.65cvss 10.0epss 0.01

    Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.

  • CVE-2026-24254CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and…

  • CVE-2026-61884CriJul 24, 2026
    risk 0.64cvss 9.8epss 0.01

    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and…

  • CVE-2019-25763CriJun 20, 2026
    risk 0.64cvss 9.8epss 0.01

    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with…

  • CVE-2026-49767CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

  • CVE-2026-49764CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

  • CVE-2026-10523CriJun 9, 2026
    risk 0.64cvss 9.9epss 0.52

    An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

  • CVE-2025-41273CriMay 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web…

  • CVE-2026-24207CriMay 20, 2026
    risk 0.64cvss 9.8epss 0.03

    NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

  • CVE-2026-40621CriMay 13, 2026
    risk 0.64cvss 9.8epss 0.00

    ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.

  • CVE-2026-40630CriApr 24, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism…