VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (686)

page 30 of 35
  • CVE-2025-6556MedJun 24, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-33939MedMay 19, 2025
    risk 0.35cvss 5.3epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.3.

  • CVE-2024-52586MedDec 9, 2024
    risk 0.35cvss 5.4epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An attacker who can authenticate…

  • CVE-2024-50334MedOct 29, 2024
    risk 0.35cvss 5.3epss 0.01

    Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive configuration data.…

  • CVE-2023-4957MedOct 11, 2023
    risk 0.35cvss 5.4epss 0.00

    A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted…

  • CVE-2022-36249MedMay 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to…

  • CVE-2019-9510MedJan 15, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP…

  • CVE-2018-19000MedFeb 5, 2019
    risk 0.35cvss 5.3epss 0.09

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.

  • CVE-2017-6871MedAug 8, 2017
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app…

  • CVE-2026-81906MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that…

  • CVE-2021-43718MedAug 18, 2026
    risk 0.34cvss 5.3epss 0.00

    An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

  • CVE-2026-40799MedJun 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.

  • CVE-2026-8990MedMay 28, 2026
    risk 0.34cvss —epss 0.00

    A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3

  • CVE-2026-3930MedMar 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-13980MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before…

  • CVE-2025-3652MedJan 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to…

  • CVE-2025-58133MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2025-52338MedAug 19, 2025
    risk 0.34cvss 5.3epss 0.01

    An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.

  • CVE-2025-26700MedFeb 17, 2025
    risk 0.34cvss 5.2epss 0.00

    Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive…

  • CVE-2024-46887MedOct 8, 2024
    risk 0.34cvss 5.3epss 0.01

    The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenticated remote attacker to gain knowledge about current actual and configured maximum cycle times as well as about…