CWE-305

Authentication Bypass by Primary Weakness

Parent: CWE-1390 - Weak Authentication

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

138 vulnerabilities with CWE-305
CVE-2026-4670 CRITICAL
Improper Authentication vulnerability in Progress MOVEit Automation
CVSS 9.8
CVE-2026-40582 CRITICAL
ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout
CVE-2026-33472 MEDIUM
Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)
CVSS 4.8
CVE-2026-20152 MEDIUM
Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability
CVSS 5.3
CVE-2026-33892 HIGH
Siemens Industrial Edge Management Pro V1 <V1.15.17 - Auth Bypass
CVSS 7.1
CVE-2026-40039 MEDIUM
Pachno 1.0.6 Open Redirection via return_to Parameter
CVSS 6.5
CVE-2026-33496 HIGH
Ory Oathkeeper has an authentication bypass by cache key confusion
CVSS 8.1
CVE-2026-3591 MEDIUM
BIND 9 - ACL Bypass via SIG(0) Use-After-Return
CVSS 5.4
CVE-2026-30849 CRITICAL
MantisBT <2.28.1 - Auth Bypass
CVSS 9.8
CVE-2026-32730 HIGH
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
CVSS 8.1
CVE-2026-3784 MEDIUM
curl - Auth Bypass
CVSS 6.5
CVE-2026-1965 MEDIUM
libcurl - Auth Bypass
CVSS 6.5
CVE-2026-3047 HIGH
Keycloak - Auth Bypass
CVSS 8.8
CVE-2026-28536 CRITICAL
Device Authentication Module - Auth Bypass
CVSS 9.6
CVE-2026-1713 MEDIUM
IBM MQ 9.1.0.0-9.4.4.1 - Privilege Escalation
CVSS 5.0
CVE-2026-0869 HIGH
Brocade ASCG 3.4.0 - Auth Bypass
CVSS 8.8
CVE-2026-22153 HIGH
Fortinet Fortios < 7.6.5 - Authentication Bypass
CVSS 8.1
CVE-2026-1290 MEDIUM
Jamf Jamf Pro <11.24 - Auth Bypass
CVE-2025-31703 LOW
Dahua NVR2-4KS3 <2026-03-03 - Privilege Escalation
CVE-2025-58382 HIGH
Brocade Fabric OS <9.2.1c2 - Command Injection
CVSS 7.2
CVE-2025-4320 CRITICAL
Birebirsoft Sufirmam <23012026 - Auth Bypass
CVSS 10.0
CVE-2025-68609 MEDIUM
Palantir's Aries - Info Disclosure
CVSS 6.6
CVE-2025-13915 CRITICAL
IBM API Connect <10.0.8.5, 10.0.11.0 - Auth Bypass
CVSS 9.8
CVE-2025-68435 CRITICAL
Zerobyte <0.18.5-0.19.0 - Auth Bypass
CVSS 9.1
CVE-2025-51663 HIGH
Lanol Filecodebox < 2.2 - Denial of Service
CVSS 7.5
Details
Vulnerabilities 138