VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (686)

page 31 of 35
  • CVE-2024-1525MedFeb 22, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password…

  • CVE-2021-4353MedOct 20, 2023
    risk 0.34cvss 5.3epss 0.01

    The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function which makes makes it possible for unauthenticated attackers…

  • CVE-2026-42303MedMay 12, 2026
    risk 0.33cvss —epss 0.00

    Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request…

  • CVE-2023-20247MedNov 1, 2023
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect…

  • CVE-2022-31022MedJun 1, 2022
    risk 0.33cvss 6.2epss 0.00

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP…

  • CVE-2020-11005MedApr 14, 2020
    risk 0.33cvss 5.1epss 0.00

    The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a…

  • CVE-2026-32031MedMar 19, 2026
    risk 0.31cvss 4.8epss 0.00

    OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoints due to path canonicalization mismatch between the gateway guard and plugin handler routing. Attackers can bypass authentication…

  • CVE-2025-6675MedJun 26, 2025
    risk 0.31cvss 4.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 before 5.0.*, from 0.0.0…

  • CVE-2025-48011MedMay 21, 2025
    risk 0.31cvss 4.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.

  • CVE-2025-48010MedMay 21, 2025
    risk 0.31cvss 4.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.

  • CVE-2024-51464MedDec 21, 2024
    risk 0.31cvss 4.3epss 0.01

    IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using…

  • CVE-2024-37893MedJun 17, 2024
    risk 0.31cvss 5.9epss 0.01

    Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use password spraying to gain access to Firefly III data using…

  • CVE-2024-21491MedFeb 13, 2024
    risk 0.31cvss 5.9epss 0.00

    Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches…

  • CVE-2023-20003MedMay 18, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login…

  • CVE-2025-43422MedNov 4, 2025
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a device may be able to disable Stolen Device Protection.

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2019-5451MedJul 30, 2019
    risk 0.30cvss 4.6epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.

  • CVE-2026-86084MedSep 8, 2026
    risk 0.29cvss 5.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and…

  • CVE-2025-48904MedJun 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-1709CriKEVFeb 21, 2024
    risk 0.29cvss 10.0epss 1.00

    ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.