CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2026-8338 CRITICAL
Authentication and Authorization Bypass in Coverity Connect
CVE-2026-12703 HIGH
Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS
CVSS 8.0
CVE-2026-18047 MEDIUM
Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash
CVSS 6.5
CVE-2026-15014 CRITICAL
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
CVSS 9.8
CVE-2026-61884 CRITICAL
Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
CVSS 9.8
CVE-2026-59545 HIGH
WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-59524 MEDIUM
WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-22049 HIGH
Netapp Ontap 9 < 9.19.1 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-43945 HIGH
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2026-61425 CRITICAL
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
CVE-2026-39385 HIGH
Frappe LMS enrollment bypass in paid courses via unrelated batch
CVE-2026-16198 MEDIUM
Sipeed PicoClaw First Run Setup access_control.go authentication bypass
CVSS 5.6
CVE-2026-57980 MEDIUM
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVSS 5.4
CVE-2026-47481 MEDIUM
Nvidia Triton Inference Server < 26.04 - Authentication Bypass Using an Alternate Path or Channel
CVSS 6.5
CVE-2026-57698 MEDIUM
WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-57697 HIGH
WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-57807 CRITICAL
WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability
CVSS 9.8
CVE-2026-36028 MEDIUM
Code 27 Companion Hub - Kiosk Restriction Bypass via Factory Reset
CVSS 6.8
CVE-2026-57867 HIGH
MicroRealEstate < 1.0.0-alpha3 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-5268 CRITICAL
CIENA 6500 S-Series - SFTP Server Authentication Weakness
CVSS 9.1
CVE-2026-58517 MEDIUM
Blocked users can create and edit WikiLambda objects
CVSS 4.3
CVE-2026-12579 HIGH
AS228T - Authentication Bypass Vulnerability
CVSS 7.4
CVE-2026-20460 MEDIUM
MediaTek Chipset - Authentication Bypass Using an Alternate Path or Channel
CVSS 5.3
CVE-2026-20459 MEDIUM
MediaTek Chipset - Authentication Bypass Using an Alternate Path or Channel
CVSS 5.3
CVE-2026-58172 CRITICAL
Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests
CVSS 9.1
Details
Vulnerabilities 612