Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-424 (对候选路径的不恰当保护) — Vulnerability Class 37

37 vulnerabilities classified as CWE-424 (对候选路径的不恰当保护). AI Chinese analysis included.

CWE-424, Improper Protection of Alternate Path, is a security weakness where a system fails to adequately secure all potential access routes to restricted resources or functionality. This vulnerability typically arises when developers implement access controls for primary interfaces but neglect secondary channels, such as administrative backdoors, debug modes, or alternative API endpoints. Attackers exploit this oversight by bypassing standard authentication mechanisms through these unprotected alternate paths, gaining unauthorized access to sensitive data or system privileges. To mitigate this risk, developers must adopt a comprehensive security architecture that enforces consistent access control policies across every possible interaction point. This involves rigorous threat modeling to identify all entry vectors, coupled with automated testing to verify that no alternate paths remain exposed. By ensuring uniform protection standards, organizations can prevent attackers from circumventing security measures through overlooked system components.

MITRE CWE Description
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Common Consequences (1)
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
Mitigations (1)
Architecture and Design Deploy different layers of protection to implement security in depth.
CVE ID Title CVSS Severity Published
CVE-2026-37008 CrewAI 权限许可和访问控制问题漏洞 — CrewAI 8.1 High 2026-09-13
CVE-2026-82586 AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes — ash_lua 8.2 High 2026-09-07
CVE-2026-82754 ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls — ash_authentication_oauth2_server 6.3 Medium 2026-09-07
CVE-2026-86145 pcre pcre2 权限许可和访问控制问题漏洞 — PCRE2 8.2 High 2026-09-05
CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) — Gitea Open Source Git Server - - 2026-08-13
CVE-2026-66756 Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false — Apache Tika 6.9 Medium 2026-07-30
CVE-2026-54423 OpenStack Ironic 权限许可和访问控制问题漏洞 — Ironic 8.2 High 2026-07-10
CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux — Prisma Access Agent - - 2026-06-10
CVE-2026-0237 Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass — Prisma Browser - - 2026-05-13
CVE-2026-4913 Ivanti Neurons for ITSM 安全漏洞 — Neurons for ITSM (On-Premise) 5.7 Medium 2026-04-14
CVE-2026-4270 AWS API MCP File Access Restriction Bypass — AWS API MCP Server 5.5 Medium 2026-03-16
CVE-2025-68939 Gitea 安全漏洞 — Gitea 8.2 High 2025-12-26
CVE-2025-4617 Prisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma Browser — Prisma Browser 5.5 - 2025-11-14
CVE-2025-58079 NEOJAPAN desknets NEO 安全漏洞 — desknet's NEO 8.1AI High AI 2025-10-16
CVE-2025-6250 Privilege Management for Windows - Elevation of Privilege — Privilege Management for Windows 8.8AI High AI 2025-07-28
CVE-2025-49162 Arris VIP1113 安全漏洞 — VIP1113 6.4 Medium 2025-06-02
CVE-2025-49163 Arris VIP1113 安全漏洞 — VIP1113 6.7 Medium 2025-06-02
CVE-2025-48827 Internet Brands vBulletin 安全漏洞 — vBulletin 10.0 Critical 2025-05-27
CVE-2025-48828 Internet Brands vBulletin 安全漏洞 — vBulletin 9.0 Critical 2025-05-27
CVE-2025-46654 CodiMD 安全漏洞 — CodiMD 4.9 Medium 2025-04-26
CVE-2025-46655 CodiMD 安全漏洞 — CodiMD 4.9 Medium 2025-04-26
CVE-2024-58136 Yii 安全漏洞 — Yii 9.0 Critical 2025-04-10
CVE-2025-0113 Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker Containers — Cortex XDR Broker VM 7.4 - 2025-02-12
CVE-2023-52952 Siemens HiMed Cockpit 安全漏洞 — HiMed Cockpit 12 pro 8.5 High 2024-10-08
CVE-2024-8311 Improper Protection of Alternate Path in GitLab — GitLab 6.5 Medium 2024-09-12
CVE-2024-3927 Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass — Element Pack – Widgets, Templates & Addons for Elementor 5.3 Medium 2024-05-22
CVE-2024-3460 KioWare 安全漏洞 — Kioware 7.4 High 2024-05-09
CVE-2024-3459 KioWare 安全漏洞 — Kioware 8.4 High 2024-05-09
CVE-2023-20272 Cisco Identity Services Engine 安全漏洞 — Cisco Identity Services Engine Software 6.7 Medium 2023-11-21
CVE-2023-46176 IBM MQ privilege escalation — MQ Appliance 6.7 Medium 2023-11-03

Vulnerabilities classified as CWE-424 (对候选路径的不恰当保护) represent 37 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.