Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-288 (使用候选路径或通道进行的认证绕过) — Vulnerability Class 585

585 vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过). AI Chinese analysis included.

CWE-288 represents a critical authentication weakness where a system enforces security controls on primary interfaces while neglecting them on alternate paths or channels. Attackers typically exploit this by identifying overlooked entry points, such as administrative APIs, debug endpoints, or legacy protocols, which lack proper credential verification. By bypassing the main authentication gate, adversaries gain unauthorized access to sensitive data or functionality without needing valid credentials. To mitigate this risk, developers must adopt a comprehensive security architecture that treats all access channels equally. This involves implementing centralized authentication mechanisms across every interface, conducting rigorous code reviews to identify hidden endpoints, and performing thorough penetration testing that specifically targets non-standard access routes. Ensuring consistent security policies prevents attackers from exploiting these structural gaps to compromise system integrity.

MITRE CWE Description
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Architecture and Design Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Examples (1)
Register SECURE_ME is located at address 0xF00. A mirror of this register called COPY_OF_SECURE_ME is at location 0x800F00. The register SECURE_ME is protected from malicious agents and only allows access to select, while COPY_OF_SECURE_ME is not. Access control is implemented using an allowlist (as indicated by a…
module foo_bar(data_out, data_in, incoming_id, address, clk, rst_n); output [31:0] data_out; input [31:0] data_in, incoming_id, address; input clk, rst_n; wire write_auth, addr_auth; reg [31:0] data_out, acl_oh_allowlist, q; assign write_auth = | (incoming_id & acl_oh_allowlist) ? 1 : 0; always @* acl_oh_allowlist <= 32'h8312; assign addr_auth = (address == 32'hF00) ? 1: 0; always @ (posedge clk or negedge rst_n) if (!rst_n) begin q <= 32'h0; data_out <= 32'h0; end else begin q <= (addr_auth & write_auth) ? data_in: q; data_out <= q; end end endmodule
Informative · Verilog
assign addr_auth = (address == 32'hF00) ? 1: 0;
Bad · Verilog
CVE ID Title CVSS Severity Published
CVE-2026-107194 Sungrow iSolarCloud <2026 认证绕过漏洞 — iSolarCloud 9.2 Critical 2026-10-07
CVE-2026-19572 FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability — FlexNet Publisher 9.3 Critical 2026-10-07
CVE-2026-100518 WordPress Advanced Google reCAPTCHA plugin <= 5.40 - Broken Authentication vulnerability — Advanced Google reCAPTCHA 5.3 Medium 2026-10-06
CVE-2026-39793 WordPress Simple JWT Login plugin 4.0.0 - Broken Authentication vulnerability — Simple JWT Login 8.8 High 2026-10-06
CVE-2026-39769 WordPress Graphina plugin <= 3.1.12 - Broken Authentication vulnerability — Graphina 7.5 High 2026-10-06
CVE-2026-100261 JetBrains YouTrack 2026.2.18991前权限绕过漏洞 — YouTrack 5.4 Medium 2026-09-30
CVE-2026-63493 Snipe-IT: 2FA bypass via the API token flow — snipe-it 8.6 High 2026-09-24
CVE-2026-90481 Burp Suite DAST <2026.8 身份验证绕过 — Burp Suite DAST 9.2 Critical 2026-09-24
CVE-2026-79680 Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module — qt 4.5 Medium 2026-09-24
CVE-2026-93928 WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerability — Taxi Booking Manager for WooCommerce 7.3 High 2026-09-22
CVE-2026-58269 Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` — server 8.1 High 2026-09-21
CVE-2026-81868 Steeltoe: Header-forwarded client cert lacks proof of private-key possession — security-advisories 6.5 Medium 2026-09-17
CVE-2026-62101 WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability — EduAdmin Booking 9.8 Critical 2026-09-17
CVE-2026-14917 Kong API Gateway Enterprise: SAML Authentication bypass — Kong Enterprise Gateway 7.7 High 2026-09-16
CVE-2026-27546 Authentication Bypass in _account_log — ICE2-8IOL1-G65L-V1D 9.8 Critical 2026-09-16
CVE-2026-91143 goproxy through 15.3 Authentication Bypass via CONNECT — goproxy 7.2 High 2026-09-14
CVE-2026-88260 Brains Zenius EMS 输入验证错误漏洞 — Zenius EMS 8.0 8.7 High 2026-09-11
CVE-2026-81906 [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks — Concrete CMS 6.3 Medium 2026-09-10
CVE-2026-81796 WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability — WP Travel 7.3 High 2026-09-10
CVE-2026-81787 WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability — IMPress for IDX Broker 6.5 Medium 2026-09-10
CVE-2026-81783 WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerability — MailMunch – Grow your Email List 7.1 High 2026-09-10
CVE-2026-88861 Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization — capgo.app 8.3 High 2026-09-10
CVE-2026-86084 n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions — n8n 6.0 Medium 2026-09-08
CVE-2026-83527 Ivanti Sentry 授权问题漏洞 — Sentry 8.1 High 2026-09-08
CVE-2026-62650 Siemens Reyrolle 7SR5 授权问题漏洞 — Reyrolle 7SR5 8.8 High 2026-09-08
CVE-2026-76169 fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers — fastify 7.5 High 2026-09-04
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability — Microsoft Entra 9.1 Critical 2026-09-03
CVE-2026-84777 WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability — Really Simple SSL 7.4 High 2026-09-03
CVE-2026-16647 Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 — Disable Login Page - - 2026-09-02
CVE-2026-81168 CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105 — CAPTCHA Protected Page - - 2026-09-02

Vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过) represent 585 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.