← Back
CWE-288

658 CVEs • Abstraction: Base

Authentication Bypass Using an Alternate Path or Channel

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

JSON object

Loading...

CVEs (658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 31, 2026
Aug 18, 2026
9.1 CRITICAL· v4
N/A· v3
N/A· v2
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via a...Show more
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypassShow less
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
-
-
Aug 20, 2026
Aug 18, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
-
-
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can...Show more
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.Show less
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
N/A· v3
N/A· v2
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
-
-
Aug 26, 2026
Aug 12, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7....Show more
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>Show less
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a l...Show more
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.Show less
-
-
Aug 26, 2026
Aug 10, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl...Show more
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication gate to be bypassed by supplying an arbitrary string as docId.Show less
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
-
-
Aug 12, 2026
Aug 6, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
1Nvidia
1Dynamo
Aug 7, 2026
Aug 4, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalati...Show more
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.Show less
-
-
Sep 3, 2026
Aug 4, 2026
9.5 CRITICAL· v4
N/A· v3
N/A· v2
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.