VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 31 of 32
  • CVE-2025-68710LowMay 26, 2026
    risk 0.16cvss 2.4epss 0.00

    Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating…

  • CVE-2024-42178LowApr 17, 2025
    risk 0.16cvss 2.5epss 0.00

    HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.

  • CVE-2020-4050LowJun 12, 2020
    risk 0.16cvss 3.5epss 0.01

    In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This…

  • CVE-2026-18577HigKEVAug 2, 2026
    risk 0.12cvss 8.1epss 0.04

    An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

  • CVE-2026-34372LowMar 31, 2026
    risk 0.11cvss 2.7epss 0.00

    Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the…

  • CVE-2025-3639LowAug 18, 2025
    risk 0.06cvss epss 0.01

    Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 and 7.3 GA through update 36 allows unauthenticated…

  • CVE-2026-33591CriAug 3, 2026
    risk 0.00cvss epss 0.01

    A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

  • CVE-2026-8338CriJul 29, 2026
    risk 0.00cvss epss 0.00

    A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on…

  • CVE-2026-12703HigJul 29, 2026
    risk 0.00cvss 8.0epss 0.00

    TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected…

  • CVE-2026-15014CriJul 28, 2026
    risk 0.00cvss 9.8epss 0.00

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the…

  • CVE-2026-59545HigJul 23, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

  • CVE-2026-59524MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

  • CVE-2026-22049HigJul 22, 2026
    risk 0.00cvss epss 0.00

    ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

  • CVE-2026-61425CriJul 20, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

  • CVE-2026-39385HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

  • CVE-2026-16198MedJul 19, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication…

  • CVE-2026-57980MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-47481MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information…

  • CVE-2026-57698MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

  • CVE-2026-57697HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.