VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 32 of 32
  • CVE-2026-57807CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.

  • CVE-2026-36028MedJul 8, 2026
    risk 0.00cvss 6.8epss 0.00

    A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset

  • CVE-2026-57867HigJul 7, 2026
    risk 0.00cvss epss 0.00

    MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through…

  • CVE-2026-5268CriJul 6, 2026
    risk 0.00cvss 9.1epss 0.00

    An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem.…

  • CVE-2025-13475LowJul 4, 2026
    risk 0.00cvss 3.5epss 0.00

    In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name…

  • CVE-2026-12579HigJul 1, 2026
    risk 0.00cvss 7.4epss 0.00

    AS228T with Authentication Bypass Vulnerability

  • CVE-2026-20460MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is…

  • CVE-2026-20459MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-58172CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.00

    Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requests. The WebSocket upgrade pipeline branch configured via MapWhen in…

  • CVE-2026-53576CriJun 26, 2026
    risk 0.00cvss 10.0epss 0.02

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a…

  • CVE-2026-56029HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

  • CVE-2026-54817MedJun 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

  • CVE-2026-27707HigFeb 27, 2026
    risk 0.00cvss 7.3epss 0.01

    Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an authentication guard logic flaw in `POST /api/v1/auth/jellyfin` allows an unauthenticated attacker to register a new Seerr account…

  • CVE-2025-53099HigJul 1, 2025
    risk 0.00cvss 7.5epss 0.01

    Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a race condition and improper handling of authorization code within Sentry to maintain…

  • CVE-2024-1646HigApr 16, 2024
    risk 0.00cvss 8.2epss 0.01

    parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict access, which is inadequate when the application is bound to a specific interface,…

  • CVE-2022-1681HigMay 12, 2022
    risk 0.00cvss 7.2epss 0.02

    Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

  • CVE-2022-24813MedApr 4, 2022
    risk 0.00cvss 5.3epss 0.01

    CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the `master` branch of CreateWiki's…

  • CVE-2012-2356Jul 21, 2012
    risk 0.00cvss epss 0.01

    The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

  • CVE-2010-3700Oct 29, 2010
    risk 0.00cvss epss 0.02

    VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.