Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-288 (使用候选路径或通道进行的认证绕过) — Vulnerability Class 585

585 vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过). AI Chinese analysis included.

CWE-288 represents a critical authentication weakness where a system enforces security controls on primary interfaces while neglecting them on alternate paths or channels. Attackers typically exploit this by identifying overlooked entry points, such as administrative APIs, debug endpoints, or legacy protocols, which lack proper credential verification. By bypassing the main authentication gate, adversaries gain unauthorized access to sensitive data or functionality without needing valid credentials. To mitigate this risk, developers must adopt a comprehensive security architecture that treats all access channels equally. This involves implementing centralized authentication mechanisms across every interface, conducting rigorous code reviews to identify hidden endpoints, and performing thorough penetration testing that specifically targets non-standard access routes. Ensuring consistent security policies prevents attackers from exploiting these structural gaps to compromise system integrity.

MITRE CWE Description
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Architecture and Design Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Examples (1)
Register SECURE_ME is located at address 0xF00. A mirror of this register called COPY_OF_SECURE_ME is at location 0x800F00. The register SECURE_ME is protected from malicious agents and only allows access to select, while COPY_OF_SECURE_ME is not. Access control is implemented using an allowlist (as indicated by a…
module foo_bar(data_out, data_in, incoming_id, address, clk, rst_n); output [31:0] data_out; input [31:0] data_in, incoming_id, address; input clk, rst_n; wire write_auth, addr_auth; reg [31:0] data_out, acl_oh_allowlist, q; assign write_auth = | (incoming_id & acl_oh_allowlist) ? 1 : 0; always @* acl_oh_allowlist <= 32'h8312; assign addr_auth = (address == 32'hF00) ? 1: 0; always @ (posedge clk or negedge rst_n) if (!rst_n) begin q <= 32'h0; data_out <= 32'h0; end else begin q <= (addr_auth & write_auth) ? data_in: q; data_out <= q; end end endmodule
Informative · Verilog
assign addr_auth = (address == 32'hF00) ? 1: 0;
Bad · Verilog
CVE ID Title CVSS Severity Published
CVE-2026-33543 FOSSBilling: Authentication bypass allows unauthenticated administrator creation — FOSSBilling - - 2026-06-24
CVE-2026-53622 Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts — traefik 7.8 High 2026-06-23
CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass — traefik 7.8 High 2026-06-23
CVE-2026-48020 Traefik StripPrefix Route-Level Auth Bypass via Path Normalization — traefik 7.8 High 2026-06-23
CVE-2026-56243 Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane — Capgo 8.1 High 2026-06-23
CVE-2020-37255 WordPress Time Capsule Plugin 1.21.16 Authentication Bypass — Time Capsule Plugin 7.5 High 2026-06-20
CVE-2019-25763 WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass — Ultimate Addons for Beaver Builder 9.8 Critical 2026-06-20
CVE-2026-50194 Steeltoe vulnerable to management-port isolation bypass via spoofed Host header — Steeltoe.Management.Endpoint 8.2 High 2026-06-17
CVE-2026-54817 WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability — MStore API 6.5 Medium 2026-06-17
CVE-2026-54804 WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability — Melhor Envio 7.6 High 2026-06-17
CVE-2026-49767 WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability — wpForo Forum 9.8 Critical 2026-06-17
CVE-2026-49071 WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vulnerability — WooCommerce Dropshipping 6.5 Medium 2026-06-17
CVE-2026-42629 WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authentication vulnerability — PowerPack Pro for Elementor 8.8 High 2026-06-17
CVE-2026-25439 WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability — Booknetic 8.1 High 2026-06-17
CVE-2026-12225 syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent — Secure Login (2FA) for Jira - - 2026-06-16
CVE-2026-49764 WordPress RegistrationMagic plugin <= 6.0.8.6 - Broken Authentication vulnerability — RegistrationMagic 9.8 Critical 2026-06-15
CVE-2026-48970 WordPress Really Simple SSL plugin <= 9.5.10 - Broken Authentication vulnerability — Really Simple SSL 8.1 High 2026-06-15
CVE-2026-42668 WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Broken Authentication vulnerability — Email Marketing for WooCommerce by Omnisend 7.5 High 2026-06-15
CVE-2026-42411 WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vulnerability — CloudSecure WP Security 8.1 High 2026-06-15
CVE-2026-42378 WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability — WP Full Stripe Free 6.5 Medium 2026-06-15
CVE-2026-40799 WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability — Simple Cloudflare Turnstile 5.8 Medium 2026-06-15
CVE-2026-40790 WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability — WP SMS 6.5 Medium 2026-06-15
CVE-2026-40785 WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability — AutomatorWP 7.1 High 2026-06-15
CVE-2026-40781 WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability — ReviewX 7.5 High 2026-06-15
CVE-2026-39450 WordPress FunnelKit Automations plugin <= 3.7.3 - Broken Authentication vulnerability — FunnelKit Automations 7.1 High 2026-06-15
CVE-2026-49062 WordPress Faust.js plugin <= 1.8.7 - Broken Authentication vulnerability — Faust.js 8.8 High 2026-06-15
CVE-2026-10523 Ivanti Sentry 安全漏洞 — Sentry 9.9 Critical 2026-06-09
CVE-2026-5415 WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link — Advanced Google reCAPTCHA 8.8 High 2026-06-05
CVE-2026-40780 WordPress BookIt plugin < 2.5.4.1 - Broken Authentication vulnerability — BookIt 7.5 High 2026-06-02
CVE-2026-42654 WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authentication vulnerability — Wallet System for WooCommerce 7.1 High 2026-06-02

Vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过) represent 585 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.