CWE•Base•Incomplete•20 recent CVEs
CWE-288Authentication Bypass Using an Alternate Path or Channel
Description
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common consequences
- Access Control→Bypass Protection Mechanism
Potential mitigations
- Architecture and DesignFunnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-83382026-07-29CVE-2026-127038.02026-07-29CVE-2026-180476.52026-07-28CVE-2026-150149.82026-07-28CVE-2026-618849.82026-07-24CVE-2026-595458.12026-07-23CVE-2026-595246.52026-07-23CVE-2026-220492026-07-22CVE-2026-439452026-07-21CVE-2026-614252026-07-20CVE-2026-393852026-07-20CVE-2026-161985.62026-07-19CVE-2026-579805.42026-07-17CVE-2026-474816.52026-07-14CVE-2026-576986.52026-07-13CVE-2026-576977.52026-07-13CVE-2026-578079.82026-07-10CVE-2026-360286.82026-07-08CVE-2026-578672026-07-07CVE-2026-52689.12026-07-06