CWE-288
658 CVEs • Abstraction: Base
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVEs (658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via a...Show more |
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. |
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. |
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. |
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. |
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can...Show more |
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. |
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. |
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. |
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7....Show more |
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a l...Show more |
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl...Show more |
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions. |
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions. |
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. |
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalati...Show more |
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. |