CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2026-39450 HIGH
WordPress FunnelKit Automations plugin <= 3.7.3 - Broken Authentication vulnerability
CVSS 7.1
CVE-2026-49062 HIGH
WordPress Faust.js plugin <= 1.8.7 - Broken Authentication vulnerability
CVSS 8.8
CVE-2026-47200 MEDIUM
Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
CVSS 5.3
CVE-2026-10523 CRITICAL
Ivanti Sentry - Authentication Bypass Using an Alternate Path or Channel
CVSS 9.9
CVE-2026-5415 HIGH
WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link
CVSS 8.8
CVE-2026-36175 MEDIUM
GNCC GP5 v7.1.76 - Authentication Bypass via U-Boot Kernel Boot Argument Injection
CVSS 6.8
CVE-2026-42654 HIGH
WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authentication vulnerability
CVSS 7.1
CVE-2026-40780 HIGH
WordPress BookIt plugin < 2.5.4.1 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-45577 MEDIUM
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
CVE-2026-8697 HIGH
Improper Authentication Rate Limiting on TP-Link's Archer C64
CVSS 8.8
CVE-2026-8990 MEDIUM
Authentication Bypass in Kidsview
CVE-2026-35090 CRITICAL
Authentication Bypass in Slican telephone exchanges
CVE-2026-35087 CRITICAL
Authentication Bypass in Slican telephone exchanges
CVE-2026-42760 HIGH
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-42749 HIGH
WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability
CVSS 7.1
CVE-2026-42745 HIGH
WordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authentication vulnerability
CVSS 7.3
CVE-2026-42735 HIGH
WordPress KiviCare plugin <= 4.3.0 - Broken Authentication vulnerability
CVSS 8.2
CVE-2026-45217 MEDIUM
WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-33843 CRITICAL
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVSS 9.1
CVE-2026-8598 CRITICAL
Unauthenticated Export Service in ZKTeco CCTV Cameras
CVSS 9.1
CVE-2026-24207 CRITICAL
Nvidia Triton Inference Server - Authentication Bypass Using an Alternate Path or Channel
CVSS 9.8
CVE-2026-24206 HIGH
Nvidia Triton Inference Server < r26.03 - Authentication Bypass Using an Alternate Path or Channel
CVSS 7.3
CVE-2026-4320 CRITICAL
Authorization Bypass in ICMS Content Management by Creartia Internet Consulting
CVE-2026-4524 MEDIUM
Authentication Bypass Using an Alternate Path or Channel in GitLab
CVSS 6.5
CVE-2026-45109 HIGH
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVSS 7.5
Details
Vulnerabilities 612