← Back
CWE-288

658 CVEs • Abstraction: Base

Authentication Bypass Using an Alternate Path or Channel

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

JSON object

Loading...

CVEs (658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 22, 2026
Jun 17, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to lis...Show more
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middleware responsible for restricting access to the endpoints uses the `Host` HTTP header rather than the actual network socket port. Versions 3.4.0 and 4.2.0 patch the issue. If an immediate upgrade to a patched version is not possible, add explicit ASP.NET Core authorization (`RequireAuthorization`) to all sensitive actuator endpoints as a defense-in-depth measure independent of port isolation and/or configure the reverse proxy or load balancer to enforce the `Host` header value and prevent clients from setting an arbitrary port.Show less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.
-
-
Jun 21, 2026
Jun 16, 2026
8.7 HIGH· v4
N/A· v3
N/A· v2
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authent...Show more
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings such as AtlassianMobileApp or JIRA. When such a User-Agent is present, the plugin does not enforce the configured 2FA checks for protected web resources. Successful exploitation allows the attacker to access the affected Atlassian application as the compromised user without completing 2FA. If the compromised account has administrative privileges, the attacker can access administrative functionality and may disable the 2FA plugin or make arbitrary administrative changes. The issue is fixed in version 3.5.0.0.Show less
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.
1Nuxt
2Nuxt
Nuxt/nitro Server
Jun 17, 2026
Jun 12, 2026
6.3 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before...Show more
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experimental.componentIslands is enabled (default in Nuxt 4), any .server.vue file under pages/ is automatically registered as a server island under the key page_<routeName> and exposed via the /__nuxt_island/:name endpoint. Until this fix, requests through that endpoint rendered the page component directly via the SSR renderer without instantiating Vue Router, which meant route middleware declared on the page (including definePageMeta({ middleware })) did not run. This issue has been patched in versions 3.21.6 and 4.4.6.Show less