CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2026-53576
CRITICAL
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
CVSS 10.0
CVE-2026-56029
HIGH
WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-55666
CRITICAL
Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth
CVE-2026-33543
CRITICAL
FOSSBilling: Authentication bypass allows unauthenticated administrator creation
CVE-2026-53622
CRITICAL
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVSS 10.0
CVE-2026-48491
CRITICAL
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
CVSS 10.0
CVE-2026-48020
CRITICAL
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
CVSS 10.0
CVE-2026-56243
HIGH
Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane
CVSS 8.1
CVE-2026-50194
HIGH
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVSS 8.2
CVE-2026-54817
MEDIUM
WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-54804
HIGH
WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability
CVSS 7.6
CVE-2026-49767
CRITICAL
WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability
CVSS 9.8
CVE-2026-49071
MEDIUM
WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-42629
HIGH
WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authentication vulnerability
CVSS 8.8
CVE-2026-25439
HIGH
WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability
CVSS 8.1
CVE-2026-12225
HIGH
syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent
CVE-2026-49764
CRITICAL
WordPress RegistrationMagic plugin <= 6.0.8.6 - Broken Authentication vulnerability
CVSS 9.8
CVE-2026-48970
HIGH
WordPress Really Simple SSL plugin <= 9.5.10 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-42668
HIGH
WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-42411
HIGH
WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-42378
MEDIUM
WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-40799
MEDIUM
WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability
CVSS 5.3
CVE-2026-40790
MEDIUM
WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-40785
HIGH
WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability
CVSS 7.1
CVE-2026-40781
HIGH
WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability
CVSS 7.5
Details
Vulnerabilities
612