CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2026-22341 MEDIUM
Case-Themes Booked <=3.0.0 - Auth Bypass
CVSS 6.7
CVE-2026-2540 HIGH
Micca Car Alarm System KE700 - Authentication Bypass via Replay Attack
CVE-2026-1618 HIGH
Universal Software Inc. FlexCity/Kiosk <1.0.36 - Privilege Escalation
CVSS 8.8
CVE-2026-1603 HIGH KEV
Ivanti Endpoint Manager < 2024 SU5 - Unauthenticated Credential Data Leak
CVSS 8.6
CVE-2026-2096 CRITICAL
Agentflow - Unauthenticated Database Manipulation via Missing Authentication
CVSS 9.8
CVE-2026-2095 CRITICAL
Flowring Agentflow - Unauthenticated Authentication Bypass via Arbitrary Token Generation
CVSS 9.8
CVE-2026-0948 MEDIUM
Drupal Microsoft Entra ID SSO Login < 1.0.4 - Authentication Bypass via Alternate Path
CVSS 6.5
CVE-2026-24858 CRITICAL KEV
Fortinet FortiAnalyzer 7.0.0-7.0.15, 7.2.0-7.2.11, 7.4.0-7.4.9, 7.6.0-7.6.5 - Authentication Bypass via FortiCloud SSO
CVSS 9.8
CVE-2026-23760 CRITICAL KEV
SmarterTools SmarterMail <9511 - Auth Bypass
CVSS 9.8
CVE-2026-22037 HIGH
@fastify/express <4.0.3 - Auth Bypass
CVSS 8.4
CVE-2026-21411 HIGH
OpenBlocks IoT DX1/EX/BX/IX9/VX2/IDM RX1 < FW5.0.8 - Unauthenticated Authentication Bypass
CVSS 8.8
CVE-2025-13475 LOW
WSO2 Identity Server and API Manager - Cross-Tenant Unauthorized Data Access
CVSS 3.5
CVE-2025-41273 CRITICAL
Waterfall WF-500 < 7.9.1.0 R2502171040 - Authentication Bypass Using an Alternate Path or Channel
CVSS 9.8
CVE-2025-68711 LOW
AppLockZ App Lock and Fingerprint Lock 4.2.11 - Unauthenticated PIN Lock Bypass via Insecure Navigation
CVSS 2.4
CVE-2025-68708 LOW
SailingLab AppLock 4.3.8 - Unauthenticated PIN Lock Bypass via Insecure Intent Navigation
CVSS 2.4
CVE-2025-68710 LOW
Easyelife App lock 1.9.2 - Unauthenticated PIN Lock Bypass via Insecure Navigation Flows
CVSS 2.4
CVE-2025-70082 CRITICAL
Lantronix EDS3000PS 3.1.0.0R2 - Code Injection
CVSS 9.8
CVE-2025-67041 CRITICAL
Lantronix EDS3000PS 3.1.0.0R2 - Command Injection
CVSS 9.8
CVE-2025-67039 CRITICAL
Lantronix EDS3000PS 3.1.0.0R2 - Auth Bypass
CVSS 9.1
CVE-2025-69985 CRITICAL
FUXA < 1.2.8 - Unauthenticated Authentication Bypass and Remote Code Execution via Referer Header Spoofing
CVSS 9.8
CVE-2025-68895 MEDIUM
AhaChat Messenger Marketing <=1.1 - Auth Bypass
CVSS 6.5
CVE-2025-67998 HIGH
Miraculous Elementor <=2.0.7 - Auth Bypass
CVSS 8.8
CVE-2025-13986 MEDIUM
Drupal Disable Login Page < 1.1.3 - Authentication Bypass via Alternate Path
CVSS 4.2
CVE-2025-13980 MEDIUM
CKEditor 5 Premium Features < 1.2.10, 1.3.0-1.3.5, 1.4.0-1.4.2, 1.5.0, 1.6.0-1.6.3 - Authentication Bypass
CVSS 5.3
CVE-2025-21589 CRITICAL
Juniper Networks Session Smart Router <5.6.17-6.1.12-lts-6.2.8-lts-...
CVSS 9.8
Details
Vulnerabilities 612