CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2026-35634 MEDIUM
OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway
CVSS 5.1
CVE-2026-31271 CRITICAL
megagao production_ssm 1.0 - Auth Bypass
CVSS 9.8
CVE-2026-30079 CRITICAL
OpenAirInterface V2.2.0 AMF - Auth Bypass
CVSS 9.8
CVE-2026-31151 CRITICAL
Kaleris Yard Management Solutions 7.2.2.1 - Authentication Bypass via Login Mechanism
CVSS 9.8
CVE-2026-5557 MEDIUM
badlogic pi-mono pi-mom Slack Bot slack.ts authentication bypass
CVSS 6.3
CVE-2026-34581 HIGH
goshs has Auth Bypass via Share Token
CVSS 8.1
CVE-2026-33950 CRITICAL
signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
CVSS 9.4
CVE-2026-29139 CRITICAL
SEPPmail Secure Email Gateway - GINA State Confusion Account Takeover
CVSS 9.8
CVE-2026-34372 LOW
Sulu checks fix permissions for subentities endpoints
CVSS 2.7
CVE-2026-34040 HIGH
Moby: AuthZ plugin bypass with oversized request body
CVSS 8.8
CVE-2026-32678 HIGH
BUFFALO Wi-Fi router products - Unauthenticated Authentication Bypass
CVSS 7.5
CVE-2026-3531 MEDIUM
OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026
CVSS 6.5
CVE-2026-2745 MEDIUM
Authentication Bypass Using an Alternate Path or Channel in GitLab
CVSS 6.8
CVE-2026-27049 CRITICAL
WordPress Jobica Core plugin <= 1.4.2 - Account Takeover vulnerability
CVSS 9.8
CVE-2026-25406 HIGH
WordPress Tutor LMS Pro plugin <= 3.9.4 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-25357 HIGH
WordPress Ultimate Membership Pro plugin <= 13.7 - Account Takeover vulnerability
CVSS 8.1
CVE-2026-25035 CRITICAL
WordPress Contest Gallery plugin <= 28.1.2.2 - Account Takeover vulnerability
CVSS 9.8
CVE-2026-25002 HIGH
WordPress LearnPress – Sepay Payment plugin <= 4.0.0 - Broken Authentication vulnerability
CVSS 7.5
CVE-2026-24359 HIGH
WordPress Dokan plugin <= 4.2.4 - Broken Authentication vulnerability
CVSS 8.8
CVE-2026-3214 MEDIUM
CAPTCHA - Moderately critical - Access bypass - SA-CONTRIB-2026-015
CVSS 6.5
CVE-2026-1917 MEDIUM
Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008
CVSS 4.3
CVE-2026-33315 MEDIUM
Vikunja <2.2.0 CalDAV Basic Auth - Two-Factor Authentication Bypass
CVSS 4.3
CVE-2026-4700 CRITICAL
Mitigation bypass in the Networking: HTTP component
CVSS 9.8
CVE-2026-23480 HIGH
Blinko: Low Privilege User Privilege Escalation - upsertUser Endpoint
CVSS 8.8
CVE-2026-22733 HIGH
Authentication Bypass under Actuator CloudFoundry endpoints
CVSS 8.2
Details
Vulnerabilities 612