CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2026-53576 CRITICAL
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
CVSS 10.0
CVE-2026-56029 HIGH
WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-55666 CRITICAL
Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth
CVE-2026-33543 CRITICAL
FOSSBilling: Authentication bypass allows unauthenticated administrator creation
CVE-2026-53622 CRITICAL
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVSS 10.0
CVE-2026-48491 CRITICAL
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
CVSS 10.0
CVE-2026-48020 CRITICAL
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
CVSS 10.0
CVE-2026-56243 HIGH
Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane
CVSS 8.1
CVE-2026-50194 HIGH
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVSS 8.2
CVE-2026-54817 MEDIUM
WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-54804 HIGH
WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability
CVSS 7.6
CVE-2026-49767 CRITICAL
WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability
CVSS 9.8
CVE-2026-49071 MEDIUM
WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-42629 HIGH
WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authentication vulnerability
CVSS 8.8
CVE-2026-25439 HIGH
WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability
CVSS 8.1
CVE-2026-12225 HIGH
syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent
CVE-2026-49764 CRITICAL
WordPress RegistrationMagic plugin <= 6.0.8.6 - Broken Authentication vulnerability
CVSS 9.8
CVE-2026-48970 HIGH
WordPress Really Simple SSL plugin <= 9.5.10 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-42668 HIGH
WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-42411 HIGH
WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-42378 MEDIUM
WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-40799 MEDIUM
WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability
CVSS 5.3
CVE-2026-40790 MEDIUM
WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-40785 HIGH
WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability
CVSS 7.1
CVE-2026-40781 HIGH
WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability
CVSS 7.5
Details
Vulnerabilities 612