VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 22 of 32
  • CVE-2026-8321HigMay 11, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in authentication bypass using alternate…

  • CVE-2026-22572HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.01

    An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2…

  • CVE-2025-66238HigDec 4, 2025
    risk 0.47cvss 7.2epss 0.00

    DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

  • CVE-2025-31512HigJul 22, 2025
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than…

  • CVE-2025-4687HigMay 29, 2025
    risk 0.47cvss epss 0.00

    In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge.…

  • CVE-2025-47244HigMay 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information.…

  • CVE-2025-39535HigApr 17, 2025
    risk 0.47cvss 7.2epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3.1.7.

  • CVE-2024-7027HigJul 24, 2024
    risk 0.47cvss 7.3epss 0.00

    The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the plugin. This makes it possible for…

  • CVE-2024-6635HigJul 20, 2024
    risk 0.47cvss 7.3epss 0.00

    The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any…

  • CVE-2023-39231HigOct 25, 2023
    risk 0.47cvss 7.3epss 0.01

    PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of…

  • CVE-2022-40725HigApr 25, 2023
    risk 0.47cvss 7.3epss 0.00

    PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated.

  • CVE-2022-23719HigJun 30, 2022
    risk 0.47cvss 7.2epss 0.00

    PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack…

  • CVE-2022-22189HigApr 14, 2022
    risk 0.47cvss 7.3epss 0.00

    An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently authenticated to.…

  • CVE-2020-1637HigApr 8, 2020
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured in the Infranet Controller (IC) is…

  • CVE-2019-5165HigFeb 25, 2020
    risk 0.47cvss 7.2epss 0.02

    An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web…

  • CVE-2019-5473HigSep 9, 2019
    risk 0.47cvss 7.2epss 0.02

    An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

  • CVE-2026-56243HigJun 23, 2026
    risk 0.46cvss 8.1epss 0.00

    Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext…

  • CVE-2026-50194HigJun 17, 2026
    risk 0.46cvss 8.2epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is…

  • CVE-2026-40785HigJun 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.

  • CVE-2026-39450HigJun 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.