目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-288 使用候选路径或通道进行的认证绕过 类漏洞列表 585

CWE-288 使用候选路径或通道进行的认证绕过 类弱点 585 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-288 指认证绕过漏洞,即系统虽设有认证机制,却存在无需验证的备用路径或通道。攻击者常利用该缺陷,通过未受保护的接口或隐藏入口直接访问受限资源,从而规避身份校验。开发者应确保所有访问入口均强制实施统一且严格的认证策略,全面审查系统架构,消除任何未授权访问的潜在路径,以保障系统安全性。

MITRE CWE 官方描述
CWE:CWE-288 通过备用路径或通道绕过身份验证 (Authentication Bypass Using an Alternate Path or Channel) 英文:产品需要身份验证,但产品存在一个不需要身份验证的备用路径或通道。
常见影响 (1)
Access Control Bypass Protection Mechanism
缓解措施 (1)
Architecture and Design Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
代码示例 (1)
Register SECURE_ME is located at address 0xF00. A mirror of this register called COPY_OF_SECURE_ME is at location 0x800F00. The register SECURE_ME is protected from malicious agents and only allows access to select, while COPY_OF_SECURE_ME is not. Access control is implemented using an allowlist (as indicated by a…
module foo_bar(data_out, data_in, incoming_id, address, clk, rst_n); output [31:0] data_out; input [31:0] data_in, incoming_id, address; input clk, rst_n; wire write_auth, addr_auth; reg [31:0] data_out, acl_oh_allowlist, q; assign write_auth = | (incoming_id & acl_oh_allowlist) ? 1 : 0; always @* acl_oh_allowlist <= 32'h8312; assign addr_auth = (address == 32'hF00) ? 1: 0; always @ (posedge clk or negedge rst_n) if (!rst_n) begin q <= 32'h0; data_out <= 32'h0; end else begin q <= (addr_auth & write_auth) ? data_in: q; data_out <= q; end end endmodule
Informative · Verilog
assign addr_auth = (address == 32'hF00) ? 1: 0;
Bad · Verilog
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-107194 Sungrow iSolarCloud <2026 认证绕过漏洞 — iSolarCloud 9.2 Critical 2026-10-07
CVE-2026-19572 FlexNet Publisher lmadmin SOAP认证绕过漏洞 — FlexNet Publisher 9.3 Critical 2026-10-07
CVE-2026-100518 WordPress Advanced Google reCAPTCHA <=5.40 身份验证漏洞 — Advanced Google reCAPTCHA 5.3 Medium 2026-10-06
CVE-2026-39793 WordPress Simple JWT Login 4.0.0 身份验证漏洞 — Simple JWT Login 8.8 High 2026-10-06
CVE-2026-39769 WordPress Graphina 插件 <= 3.1.12 认证缺陷漏洞 — Graphina 7.5 High 2026-10-06
CVE-2026-100261 JetBrains YouTrack 2026.2.18991前权限绕过漏洞 — YouTrack 5.4 Medium 2026-09-30
CVE-2026-63493 Snipe-IT API令牌流程双重验证绕过漏洞 — snipe-it 8.6 High 2026-09-24
CVE-2026-90481 Burp Suite DAST <2026.8 身份验证绕过 — Burp Suite DAST 9.2 Critical 2026-09-24
CVE-2026-79680 Qt VNC Server 密码身份验证机制绕过漏洞 — qt 4.5 Medium 2026-09-24
CVE-2026-93928 WordPress打车预订插件2.0.8前认证失败漏洞 — Taxi Booking Manager for WooCommerce 7.3 High 2026-09-22
CVE-2026-58269 Sync-in Server 2FA 认证绕过漏洞 — server 8.1 High 2026-09-21
CVE-2026-81868 Steeltoe 客户端证书缺少私钥持有证明 — security-advisories 6.5 Medium 2026-09-17
CVE-2026-62101 WordPress EduAdmin插件5.4.2认证失败漏洞 — EduAdmin Booking 9.8 Critical 2026-09-17
CVE-2026-14917 Kong API Gateway 企业版 SAML 认证绕过漏洞 — Kong Enterprise Gateway 7.7 High 2026-09-16
CVE-2026-27546 _account_log认证绕过漏洞 — ICE2-8IOL1-G65L-V1D 9.8 Critical 2026-09-16
CVE-2026-91143 GoProxy 15.3 及更早版本认证绕过漏洞 — goproxy 7.2 High 2026-09-14
CVE-2026-88260 Brains Zenius EMS 输入验证错误漏洞 — Zenius EMS 8.0 8.7 High 2026-09-11
CVE-2026-81906 Concrete CMS 授权问题漏洞 — Concrete CMS 6.3 Medium 2026-09-10
CVE-2026-81796 WordPress WP Travel 授权问题漏洞 — WP Travel 7.3 High 2026-09-10
CVE-2026-81787 WordPress IMPress for IDX Broker 授权问题漏洞 — IMPress for IDX Broker 6.5 Medium 2026-09-10
CVE-2026-81783 WordPress MailMunch 授权问题漏洞 — MailMunch – Grow your Email List 7.1 High 2026-09-10
CVE-2026-88861 Capgo 授权问题漏洞 — capgo.app 8.3 High 2026-09-10
CVE-2026-86084 n8n 授权问题漏洞 — n8n 6.0 Medium 2026-09-08
CVE-2026-83527 Ivanti Sentry 授权问题漏洞 — Sentry 8.1 High 2026-09-08
CVE-2026-62650 Siemens Reyrolle 7SR5 授权问题漏洞 — Reyrolle 7SR5 8.8 High 2026-09-08
CVE-2026-76169 Fastify 授权问题漏洞 — fastify 7.5 High 2026-09-04
CVE-2026-62916 Microsoft Entra 授权问题漏洞 — Microsoft Entra 9.1 Critical 2026-09-03
CVE-2026-84777 WordPress Really Simple Security 授权问题漏洞 — Really Simple SSL 7.4 High 2026-09-03
CVE-2026-16647 Drupal Disable Login Page 授权问题漏洞 — Disable Login Page - - 2026-09-02
CVE-2026-81168 Drupal CAPTCHA Protected Page 授权问题漏洞 — CAPTCHA Protected Page - - 2026-09-02

CWE-288(使用候选路径或通道进行的认证绕过) 是常见的弱点类别,本平台收录该类弱点关联的 585 条 CVE 漏洞。