CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2026-8338
CRITICAL
Authentication and Authorization Bypass in Coverity Connect
CVE-2026-12703
HIGH
Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS
CVSS 8.0
CVE-2026-18047
MEDIUM
Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash
CVSS 6.5
CVE-2026-15014
CRITICAL
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
CVSS 9.8
CVE-2026-61884
CRITICAL
Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
CVSS 9.8
CVE-2026-59545
HIGH
WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-59524
MEDIUM
WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-22049
HIGH
Netapp Ontap 9 < 9.19.1 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-43945
HIGH
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2026-61425
CRITICAL
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
CVE-2026-39385
HIGH
Frappe LMS enrollment bypass in paid courses via unrelated batch
CVE-2026-16198
MEDIUM
Sipeed PicoClaw First Run Setup access_control.go authentication bypass
CVSS 5.6
CVE-2026-57980
MEDIUM
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVSS 5.4
CVE-2026-47481
MEDIUM
Nvidia Triton Inference Server < 26.04 - Authentication Bypass Using an Alternate Path or Channel
CVSS 6.5
CVE-2026-57698
MEDIUM
WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-57697
HIGH
WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-57807
CRITICAL
WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability
CVSS 9.8
CVE-2026-36028
MEDIUM
Code 27 Companion Hub - Kiosk Restriction Bypass via Factory Reset
CVSS 6.8
CVE-2026-57867
HIGH
MicroRealEstate < 1.0.0-alpha3 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-5268
CRITICAL
CIENA 6500 S-Series - SFTP Server Authentication Weakness
CVSS 9.1
CVE-2026-58517
MEDIUM
Blocked users can create and edit WikiLambda objects
CVSS 4.3
CVE-2026-12579
HIGH
AS228T - Authentication Bypass Vulnerability
CVSS 7.4
CVE-2026-20460
MEDIUM
MediaTek Chipset - Authentication Bypass Using an Alternate Path or Channel
CVSS 5.3
CVE-2026-20459
MEDIUM
MediaTek Chipset - Authentication Bypass Using an Alternate Path or Channel
CVSS 5.3
CVE-2026-58172
CRITICAL
Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests
CVSS 9.1
Details
Vulnerabilities
612