← Back
CWE-305

153 CVEs • Abstraction: Base

Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

JSON object

Loading...

CVEs (153)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Froxlor
1Froxlor
Jun 17, 2026
Mar 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
1Modoboa
1Modoboa
Jun 17, 2026
Feb 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
2Openstack
Redhat
4Barbican
OpenstackOpenstack For Ibm Power+1 more
Jun 17, 2026
Jan 18, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
1Ikus Soft
1Rdiffweb
Jun 17, 2026
Dec 27, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
1Makedeb
1Mist
Jun 17, 2026
Sep 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system w...Show more
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permissions. Versions 0.9.5 and later contain a patch. No known workarounds exist.Show less
1Openharmony
1Openharmony
Jun 17, 2026
Sep 9, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
1Openharmony
1Openharmony
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain...Show more
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.Show less
1Openharmony
1Openharmony
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
1Joinbookwyrm
1Bookwyrm
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.
1Mepsan
1Stawiz Usc++
Jun 17, 2026
Mar 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate high privileged accounts passwords.
3Debian
FedoraprojectOpenvpn
3Debian Linux
FedoraOpenvpn
Jun 17, 2026
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be grant...Show more
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.Show less
1Google
1Android
Jun 17, 2026
Mar 4, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
1Dart
1Dart Software Development Kit
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient...Show more
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to example.com with authorization header and it redirects to an attackers site, they might not expect attacker site to receive authorization header. We recommend updating the Dart SDK to version 2.16.0 or beyond.Show less
1Valmet
1Dna
Jun 17, 2026
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012...Show more
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.Show less
1Arista
1Eos
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
2Adodb Project
Debian
2Adodb
Debian Linux
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
1Goautodial
2Goautodial
Goautodial Api
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerabl...Show more
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate the username and password incorrectly, allowing the caller to specify any values for these parameters and successfully authenticate. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:CShow less
1Openvpn
1Openvpn
Jun 17, 2026
Jul 12, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name o...Show more
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.Show less
1Openvpn
1Openvpn Access Server
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially tri...Show more
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOpenvpn+1 more
Jun 17, 2026
Apr 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further i...Show more
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.Show less