CWE-288
606 CVEs • Abstraction: Base
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVEs (606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request. |
1Pingidentity 1Pingone Mfa Integration Kit Jun 17, 2026 Oct 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability...Show more |
1Ibm 1Sterling Partner Engagement Manager Jun 17, 2026 Oct 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896. |
WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface. |
1Rightpress 1Woocommerce Dynamic Pricing & Discounts Jun 17, 2026 Oct 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function w...Show more |
A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and p...Show more |
1Furunosystems 2Acera 1310 Firmware Acera 1320 FirmwareJun 17, 2026 Oct 3, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to do...Show more |
2Kubernetes Redhat2Kube Apiserver Openshift Container PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource b...Show more |
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible |
Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass.
This issue affects Digital Yepas: before 1.0.1. |
1Doverfuelingsolutions 1Maglink Lx Web Console Configuration Jun 17, 2026 Sep 11, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseJun 17, 2026 Sep 6, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute fo...Show more |
1Webtoffee 1Stripe Payment Plugin For Woocommerce Jun 17, 2026 Aug 31, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a...Show more |
The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in a...Show more |
1Miniorange 1Web3 Crypto Wallet Login & Nft Token Gating Jun 17, 2026 Jun 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_...Show more |
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through th...Show more |
A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive m...Show more |
1Miniorange 1Wordpress Social Login And Register (discord, Google, Twitter, Linkedin) Jun 17, 2026 Jun 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on...Show more |
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot protections. An exploitation of this vulnerability may lead to a loss of...Show more |
1Tychesoftwares 1Abandoned Cart Lite For Woocommerce Jun 17, 2026 Jun 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the a...Show more |