VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 29 of 32
  • CVE-2020-11005MedApr 14, 2020
    risk 0.33cvss 5.1epss 0.00

    The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a…

  • CVE-2026-32031MedMar 19, 2026
    risk 0.31cvss 4.8epss 0.00

    OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoints due to path canonicalization mismatch between the gateway guard and plugin handler routing. Attackers can bypass authentication…

  • CVE-2025-6675MedJun 26, 2025
    risk 0.31cvss 4.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 before 5.0.*, from 0.0.0…

  • CVE-2025-48011MedMay 21, 2025
    risk 0.31cvss 4.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.

  • CVE-2025-48010MedMay 21, 2025
    risk 0.31cvss 4.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.

  • CVE-2024-51464MedDec 21, 2024
    risk 0.31cvss 4.3epss 0.01

    IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using…

  • CVE-2024-37893MedJun 17, 2024
    risk 0.31cvss 5.9epss 0.01

    Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use password spraying to gain access to Firefly III data using…

  • CVE-2024-21491MedFeb 13, 2024
    risk 0.31cvss 5.9epss 0.00

    Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches…

  • CVE-2023-20003MedMay 18, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login…

  • CVE-2025-43422MedNov 4, 2025
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a device may be able to disable Stolen Device Protection.

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2019-5451MedJul 30, 2019
    risk 0.30cvss 4.6epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.

  • CVE-2025-48904MedJun 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-1709CriKEVFeb 21, 2024
    risk 0.29cvss 10.0epss 1.00

    ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

  • CVE-2026-1917MedMar 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.

  • CVE-2026-0602MedMar 11, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to…

  • CVE-2026-1747MedFeb 25, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to…

  • CVE-2025-46286MedJan 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment.

  • CVE-2025-66200MedDec 5, 2025
    risk 0.28cvss 5.4epss 0.01

    mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through…

  • CVE-2025-9914MedOct 6, 2025
    risk 0.28cvss 4.3epss 0.00

    The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.