CWE•Base•Incomplete•20 recent CVEs
CWE-288Authentication Bypass Using an Alternate Path or Channel
Description
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common consequences
- Access Control→Bypass Protection Mechanism
Potential mitigations
- Architecture and DesignFunnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-882602026-09-11CVE-2026-819062026-09-11CVE-2026-817967.32026-09-10CVE-2026-817876.52026-09-10CVE-2026-817837.12026-09-10CVE-2026-888618.32026-09-10CVE-2026-860845.52026-09-08CVE-2026-498877.82026-09-08CVE-2026-835278.12026-09-08CVE-2026-771037.52026-09-08CVE-2026-626508.82026-09-08CVE-2026-761697.52026-09-04CVE-2026-629169.12026-09-03CVE-2026-847777.42026-09-03CVE-2026-811683.72026-09-02CVE-2026-166474.12026-09-02CVE-2026-822257.42026-08-31CVE-2026-822698.12026-08-28CVE-2026-769439.82026-08-28CVE-2026-656412026-08-26