Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-288 (使用候选路径或通道进行的认证绕过) — Vulnerability Class 585

585 vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过). AI Chinese analysis included.

CWE-288 represents a critical authentication weakness where a system enforces security controls on primary interfaces while neglecting them on alternate paths or channels. Attackers typically exploit this by identifying overlooked entry points, such as administrative APIs, debug endpoints, or legacy protocols, which lack proper credential verification. By bypassing the main authentication gate, adversaries gain unauthorized access to sensitive data or functionality without needing valid credentials. To mitigate this risk, developers must adopt a comprehensive security architecture that treats all access channels equally. This involves implementing centralized authentication mechanisms across every interface, conducting rigorous code reviews to identify hidden endpoints, and performing thorough penetration testing that specifically targets non-standard access routes. Ensuring consistent security policies prevents attackers from exploiting these structural gaps to compromise system integrity.

MITRE CWE Description
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Architecture and Design Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Examples (1)
Register SECURE_ME is located at address 0xF00. A mirror of this register called COPY_OF_SECURE_ME is at location 0x800F00. The register SECURE_ME is protected from malicious agents and only allows access to select, while COPY_OF_SECURE_ME is not. Access control is implemented using an allowlist (as indicated by a…
module foo_bar(data_out, data_in, incoming_id, address, clk, rst_n); output [31:0] data_out; input [31:0] data_in, incoming_id, address; input clk, rst_n; wire write_auth, addr_auth; reg [31:0] data_out, acl_oh_allowlist, q; assign write_auth = | (incoming_id & acl_oh_allowlist) ? 1 : 0; always @* acl_oh_allowlist <= 32'h8312; assign addr_auth = (address == 32'hF00) ? 1: 0; always @ (posedge clk or negedge rst_n) if (!rst_n) begin q <= 32'h0; data_out <= 32'h0; end else begin q <= (addr_auth & write_auth) ? data_in: q; data_out <= q; end end endmodule
Informative · Verilog
assign addr_auth = (address == 32'hF00) ? 1: 0;
Bad · Verilog
CVE ID Title CVSS Severity Published
CVE-2026-45577 Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass — neotoma - - 2026-05-29
CVE-2025-41273 Waterfall WF-500 安全漏洞 — WF-500 - - 2026-05-29
CVE-2026-8697 Improper Authentication Rate Limiting on TP-Link's Archer C64 — Archer C64 v1.0 - - 2026-05-28
CVE-2026-8990 Authentication Bypass in Kidsview — Kidsview - - 2026-05-28
CVE-2026-35090 Authentication Bypass in Slican telephone exchanges — CCT-1668 - - 2026-05-27
CVE-2026-35087 Authentication Bypass in Slican telephone exchanges — IPx - - 2026-05-27
CVE-2026-42760 WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Authentication vulnerability — Backup and Staging by WP Time Capsule 7.5 High 2026-05-27
CVE-2026-42749 WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability — Disable Comments for Any Post Types (Remove comments) 7.1 High 2026-05-27
CVE-2026-42745 WordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authentication vulnerability — Smart Online Order for Clover 7.3 High 2026-05-27
CVE-2026-42735 WordPress KiviCare plugin <= 4.3.0 - Broken Authentication vulnerability — KiviCare 8.2 High 2026-05-27
CVE-2026-45217 WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerability — Stripe Payment Gateway for WooCommerce 6.5 Medium 2026-05-25
CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability — Microsoft Entra 9.1 Critical 2026-05-22
CVE-2026-8598 Unauthenticated Export Service in ZKTeco CCTV Cameras — SSC335-GC2063-Face-0b77 Solution Camera 9.1 Critical 2026-05-20
CVE-2026-24207 NVIDIA Triton Inference Server 安全漏洞 — Triton Inference Server 9.8 Critical 2026-05-20
CVE-2026-24206 NVIDIA Triton Inference Server 安全漏洞 — Triton Inference Server 7.3 High 2026-05-20
CVE-2026-4320 Authorization Bypass in ICMS Content Management by Creartia Internet Consulting — ICMS Content Management - - 2026-05-18
CVE-2026-4524 Authentication Bypass Using an Alternate Path or Channel in GitLab — GitLab 6.5 Medium 2026-05-14
CVE-2026-45109 Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes — next.js 7.5 High 2026-05-13
CVE-2026-44574 Next.js: Middleware / Proxy bypass through dynamic route parameter injection — next.js 8.1 High 2026-05-13
CVE-2026-44575 Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes — next.js 7.5 High 2026-05-13
CVE-2026-40621 ELECOM多款产品 安全漏洞 — WRC-BE72XSD-B - - 2026-05-13
CVE-2026-42303 Fides: Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection — fides - - 2026-05-12
CVE-2026-42300 DevGuard: Unauthenticated identity assertion via `X-Admin-Token` header — devguard - - 2026-05-12
CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability — Windows 10 Version 1607 6.5 Medium 2026-05-12
CVE-2026-8321 inkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypass — agents 7.3 High 2026-05-11
CVE-2026-41308 Password Pusher: JSON API `/p.json` file upload alias bypasses file-push authentication — PasswordPusher 6.5 Medium 2026-05-08
CVE-2026-7458 User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint — User Verification by PickPlugins 9.8 Critical 2026-05-02
CVE-2026-7567 Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover — Temporary Login 9.8 Critical 2026-05-01
CVE-2026-40022 Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime — Apache Camel Platform HTTP Main 9.8AI Critical AI 2026-04-27
CVE-2026-40630 SenseLive X3050 Authentication bypass using an alternate path or channel — X3050 9.8 Critical 2026-04-23

Vulnerabilities classified as CWE-288 (使用候选路径或通道进行的认证绕过) represent 585 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.