CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2026-22731
HIGH
Authentication Bypass under Actuator Health groups paths
CVSS 8.2
CVE-2026-32031
MEDIUM
OpenClaw < 2026.2.26 - Authentication Bypass via Path Canonicalization Mismatch in /api/channels Gateway
CVSS 4.8
CVE-2026-32004
MEDIUM
OpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels Route
CVSS 6.5
CVE-2026-25471
HIGH
WordPress Admin Safety Guard plugin <= 1.2.6 - Broken Authentication vulnerability
CVSS 8.1
CVE-2026-3930
MEDIUM
Google Chrome iOS <146.0.7680.71 - Auth Bypass
CVSS 5.3
CVE-2026-32130
HIGH
ZITADEL 2.68.0-3.4.7/4.12.0-4.12.1 - Auth Bypass
CVSS 7.5
CVE-2026-0602
MEDIUM
GitLab 15.6-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Metadata Disclosure via Snippet Rendering
CVSS 4.3
CVE-2026-27842
CRITICAL
MR-GM5L-S1 & MR-GM5A-L1 - Auth Bypass
CVSS 9.8
CVE-2026-26117
HIGH
Azure Windows Virtual Machine Agent - Privilege Escalation
CVSS 7.8
CVE-2026-22572
HIGH
Fortinet FortiAnalyzer 7.6.0-7.6.3 - Auth Bypass
CVSS 7.2
CVE-2026-30777
MEDIUM
EC-CUBE 4.1.0-4.1.1 - Multi-Factor Authentication Bypass
CVSS 6.5
CVE-2026-27390
HIGH
WeDesignTech Ultimate Booking Addon <=1.0.1 - Auth Bypass
CVSS 8.8
CVE-2026-27389
CRITICAL
WeDesignTech Ultimate Booking Addon <=1.0.1 - Auth Bypass
CVSS 9.8
CVE-2026-20079
CRITICAL
Cisco Secure Firewall Management Center - Auth Bypass & RCE via Crafted HTTP Requests
CVSS 10.0
CVE-2026-2628
CRITICAL
All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <2.2.5 - Authentication Bypass
CVSS 9.8
CVE-2026-28411
CRITICAL
WeGIA < 3.6.5 - Unauthenticated PHP Variable Overwrite via extract() on $_REQUEST
CVSS 9.8
CVE-2026-27707
HIGH
Seerr 2.0.0-3.0.9 - Unauthenticated Account Registration via Jellyfin Authentication Bypass
CVSS 7.3
CVE-2026-22205
HIGH
SPIP < 4.4.10 - Unauthenticated Authentication Bypass via PHP Type Juggling
CVSS 7.5
CVE-2026-1241
HIGH
Pelco Sarix Professional 3 Series - Auth Bypass
CVE-2026-1779
HIGH
WordPress User Registration & Membership <=5.1.2 - Auth Bypass
CVSS 8.1
CVE-2026-1747
MEDIUM
GitLab 17.11-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Privilege Escalation via Conan Package Modification
CVSS 4.3
CVE-2026-27611
MEDIUM
FileBrowser Quantum <1.1.3/1.2.6 - Auth Bypass
CVSS 6.5
CVE-2026-2791
CRITICAL
Firefox <148 & ESR <140.8 - Auth Bypass
CVSS 9.8
CVE-2026-2784
CRITICAL
Firefox < 148.0 and < 140.8.0 - Authentication Bypass via DOM Security Mitigation
CVSS 9.8
CVE-2026-2775
CRITICAL
Firefox <115.33.0, 115.33-115.*, <148.0, >=148; Thunderbird <140.8.0, 140.8-140.*, >=148 - Authentication Bypass
CVSS 9.8
Details
Vulnerabilities
612