VYPR

CWE-305

Authentication Bypass by Primary Weakness

BaseDraft

Description

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (159)

page 3 of 8
  • CVE-2026-30849CriMar 23, 2026
    risk 0.57cvss 9.8epss 0.00

    Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database…

  • CVE-2026-3047HigMar 5, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This…

  • CVE-2026-0869HigMar 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within…

  • CVE-2023-36497HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.

  • CVE-2023-1307CriMar 10, 2023
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

  • CVE-2022-38700HigSep 9, 2022
    risk 0.57cvss 8.8epss 0.00

    OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.

  • CVE-2022-2818CriAug 15, 2022
    risk 0.57cvss 9.8epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

  • CVE-2021-26726HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.01

    A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.

  • CVE-2026-6266HigMay 4, 2026
    risk 0.54cvss 8.3epss 0.00

    A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to…

  • CVE-2025-54622HigAug 6, 2025
    risk 0.54cvss 8.3epss 0.00

    Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2019-14909HigDec 4, 2019
    risk 0.54cvss 8.3epss 0.01

    A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

  • CVE-2026-22153HigFeb 10, 2026
    risk 0.53cvss 8.1epss 0.01

    An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific…

  • CVE-2025-31965HigJul 29, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.

  • CVE-2025-41450HigMay 8, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to version 4.2

  • CVE-2024-12776HigMar 20, 2025
    risk 0.53cvss 8.1epss 0.01

    In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application.

  • CVE-2026-40976CriApr 28, 2026
    risk 0.52cvss 9.1epss 0.00

    In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default…

  • CVE-2026-40582CriApr 18, 2026
    risk 0.52cvss epss 0.01

    ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and…

  • CVE-2025-47776CriNov 4, 2025
    risk 0.52cvss 9.1epss 0.00

    Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentication code in versions 2.27.1 and below.PHP type juggling will cause certain MD5 hashes matching scientific notation to be…

  • CVE-2023-27582CriMar 13, 2023
    risk 0.52cvss 9.1epss 0.01

    maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified…

  • CVE-2020-36569CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.