Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-288 (使用候选路径或通道进行的认证绕过) — Vulnerability Class 585

585 vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过). AI Chinese analysis included.

CWE-288 represents a critical authentication weakness where a system enforces security controls on primary interfaces while neglecting them on alternate paths or channels. Attackers typically exploit this by identifying overlooked entry points, such as administrative APIs, debug endpoints, or legacy protocols, which lack proper credential verification. By bypassing the main authentication gate, adversaries gain unauthorized access to sensitive data or functionality without needing valid credentials. To mitigate this risk, developers must adopt a comprehensive security architecture that treats all access channels equally. This involves implementing centralized authentication mechanisms across every interface, conducting rigorous code reviews to identify hidden endpoints, and performing thorough penetration testing that specifically targets non-standard access routes. Ensuring consistent security policies prevents attackers from exploiting these structural gaps to compromise system integrity.

MITRE CWE Description
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Architecture and Design Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Examples (1)
Register SECURE_ME is located at address 0xF00. A mirror of this register called COPY_OF_SECURE_ME is at location 0x800F00. The register SECURE_ME is protected from malicious agents and only allows access to select, while COPY_OF_SECURE_ME is not. Access control is implemented using an allowlist (as indicated by a…
module foo_bar(data_out, data_in, incoming_id, address, clk, rst_n); output [31:0] data_out; input [31:0] data_in, incoming_id, address; input clk, rst_n; wire write_auth, addr_auth; reg [31:0] data_out, acl_oh_allowlist, q; assign write_auth = | (incoming_id & acl_oh_allowlist) ? 1 : 0; always @* acl_oh_allowlist <= 32'h8312; assign addr_auth = (address == 32'hF00) ? 1: 0; always @ (posedge clk or negedge rst_n) if (!rst_n) begin q <= 32'h0; data_out <= 32'h0; end else begin q <= (addr_auth & write_auth) ? data_in: q; data_out <= q; end end endmodule
Informative · Verilog
assign addr_auth = (address == 32'hF00) ? 1: 0;
Bad · Verilog
CVE ID Title CVSS Severity Published
CVE-2026-82225 WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerability — RegistrationMagic 7.4 High 2026-08-31
CVE-2026-82269 Gophish Account Lockout and Forced Password Change Bypassable via API Key — gophish 8.1 High 2026-08-28
CVE-2026-76943 Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel — Xiiaozet LK100W 9.8 Critical 2026-08-27
CVE-2026-65641 Veeam one 授权问题漏洞 — One 9.3 Critical 2026-08-26
CVE-2026-3035 Authentication Bypass Using an Alternate Path or Channel in GitLab — GitLab 5.5 Medium 2026-08-26
CVE-2026-58092 Unauthorized credential switching — FreeBSD - - 2026-08-26
CVE-2026-16639 Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 — Internationalization Single Sign-On - - 2026-08-25
CVE-2026-63587 SMS Password Authorization Bypass via Failed Attempt Counter — IE-SR-2TX-WL-4G-EU 8.6 High 2026-08-25
CVE-2026-78259 WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability — WPLegalPages 7.3 High 2026-08-24
CVE-2026-74001 WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability — User Registration & Membership Pro 9.8 Critical 2026-08-20
CVE-2026-66677 WordPress Leyka plugin <= 3.32.3 - Broken Authentication vulnerability — Leyka 7.6 High 2026-08-20
CVE-2026-24185 NVIDIA NVOS 授权问题漏洞 — NVOS 7.1 High 2026-08-18
CVE-2026-71879 Authentication bypass in Integrated Publishing Toolkit — Integrated Publishing Toolkit 9.1 Critical 2026-08-18
CVE-2026-73399 WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vulnerability — Flutterwave WooCommerce 6.5 Medium 2026-08-18
CVE-2026-73398 WordPress Piraeus Bank WooCommerce Payment Gateway plugin 3.2.0 - Broken Authentication vulnerability — Piraeus Bank WooCommerce Payment Gateway 6.5 Medium 2026-08-18
CVE-2026-73396 WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication vulnerability — MWB HubSpot for WooCommerce 7.1 High 2026-08-18
CVE-2026-73381 WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability — Popup by Supsystic 9.1 Critical 2026-08-18
CVE-2026-73379 WordPress Contact Form by Supsystic plugin < 1.10.0 - Bypass Vulnerability vulnerability — Contact Form by Supsystic 6.5 Medium 2026-08-18
CVE-2026-32481 WordPress Ezoic plugin <= 2.22.11 - Broken Authentication vulnerability — Ezoic 7.5 High 2026-08-18
CVE-2026-75627 Bastillion Authentication Bypass via Path-Prefix Routing Mismatch — Bastillion 9.8 Critical 2026-08-18
CVE-2026-75045 JetBrains YouTrack 授权问题漏洞 — YouTrack 9.1 Critical 2026-08-17
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability — Cartify 9.8 Critical 2026-08-13
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability — Salon booking system 9.8 Critical 2026-08-13
CVE-2026-70468 Fortinet fortimanager 授权问题漏洞 — FortiManager 7.3 High 2026-08-12
CVE-2026-18636 Velociraptor VFSGetBuffer API path deny list bypass — Velociraptor 6.8 Medium 2026-08-11
CVE-2026-72691 OpenSignLabs opensignserver - Authentication Bypass — opensignserver 7.5 High 2026-08-10
CVE-2026-66451 WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerability — WP Event SOlution 6.5 Medium 2026-08-06
CVE-2026-66425 WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability — Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder 6.5 Medium 2026-08-06
CVE-2026-65542 WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability — Super Socializer 8.8 High 2026-08-06
CVE-2026-24254 NVIDIA Dynamo 授权问题漏洞 — Dynamo 9.8 Critical 2026-08-04

Vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过) represent 585 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.