CWE-305

Authentication Bypass by Primary Weakness

Parent: CWE-1390 - Weak Authentication

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

154 vulnerabilities with CWE-305
CVE-2026-62427 HIGH
sysctl and platform-op locks open to abuse
CVSS 8.8
CVE-2026-9597 MEDIUM
Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
CVSS 5.4
CVE-2026-9571 MEDIUM
Mattermost 10.11/11.6/11.7 - OAuth Refresh Token Invalidation Bypass
CVSS 5.9
CVE-2026-35159 MEDIUM
Dell Inspiron 15 3520 - Authentication Bypass by Primary Weakness
CVSS 5.3
CVE-2026-10539 CRITICAL
Unauthenticated command injection in Control-M/Server communication command
CVSS 9.0
CVE-2026-41052 HIGH
Rancher Privilege Escalation from Project Owner to Host
CVSS 8.8
CVE-2026-25555 CRITICAL
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
CVSS 9.8
CVE-2026-9798 MEDIUM
Keycloak: keycloak: brute-force protection bypass in ciba flow
CVSS 4.3
CVE-2026-9047 HIGH
Devolutions Server < 2026.1.16.0 - Authentication Bypass by Primary Weakness
CVSS 7.6
CVE-2026-41054 HIGH
Missing exit out of permission check in haveged could lead to root exploit
CVSS 7.8
CVE-2026-6334 LOW
OAuth authorization code client binding not enforced during token redemption in Mattermost
CVSS 3.1
CVE-2026-2652 HIGH
Authentication Bypass in mlflow/mlflow
CVSS 8.6
CVE-2026-6266 HIGH
Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linking
CVSS 8.3
CVE-2026-4670 CRITICAL
Improper Authentication vulnerability in Progress MOVEit Automation
CVSS 9.8
CVE-2026-40976 CRITICAL
Spring Boot 4.0.0-4.0.5 - Auth Bypass
CVSS 9.1
CVE-2026-40582 CRITICAL
ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout
CVE-2026-33472 MEDIUM
Cryptomator 1.19.1 - OAuth Token Exchange HTTP Downgrade
CVSS 4.8
CVE-2026-20152 MEDIUM
Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability
CVSS 5.3
CVE-2026-33892 HIGH
Siemens Industrial Edge Management Pro V1 <V1.15.17 - Auth Bypass
CVSS 7.1
CVE-2026-40039 MEDIUM
Pachno 1.0.6 Open Redirection via return_to Parameter
CVSS 6.5
CVE-2026-33496 HIGH
Ory Oathkeeper <26.2.0 oauth2_introspection - Authentication Bypass
CVSS 8.1
CVE-2026-3591 MEDIUM
BIND 9 - ACL Bypass via SIG(0) Use-After-Return
CVSS 5.4
CVE-2026-30849 CRITICAL
MantisBT < 2.28.1 - Authentication Bypass via SOAP API Password Parameter
CVSS 9.8
CVE-2026-32730 HIGH
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
CVSS 8.1
CVE-2026-3784 MEDIUM
curl 7.7-8.18.0 - Authentication Bypass via HTTP Proxy Connection Reuse
CVSS 6.5
Details
Vulnerabilities 154