Skip to main content

About CWE-288

The direct consequence is bypass of the protection mechanism, so the access control the main path enforces does not apply.

MITRE name
Authentication Bypass Using an Alternate Path or Channel
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Incomplete

Mitigations

  • +Route all access through a single choke point so there is one path to each resource.
  • +Perform a permission check on every access to a resource, regardless of how the request arrived.
  • +Inventory all channels and interfaces, including those assumed private, and apply authentication to each.

CWE-288 Vulnerabilities

16 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-18556
Unauthenticated administrative account takeover
N-able8.27.9%KEV2026-08-01
CVE-2026-18577
Incomplete patch leads to administrative account takeover
N-able8.214.6%KEV2026-08-02
CVE-2026-1603
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Ivanti8.688.3%KEV2026-02-10
CVE-2026-24858
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet9.485.8%KEV2026-01-27
CVE-2026-23760
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
SmarterTools9.396.5%KEV2026-01-22
CVE-2025-34026
Versa Concerto Actuator Authentication Bypass Information Leak
Versa9.281.9%KEV2025-05-21
CVE-2025-2747
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
Kentico9.897.2%KEV2025-03-24
CVE-2025-2746
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
Kentico9.873.0%KEV2025-03-24
CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
FreePBX10.086.3%KEV2025-08-28
CVE-2025-4427
Authentication Bypass
Ivanti5.399.9%KEV2025-05-13
CVE-2025-24472
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet8.17.2%KEV2025-02-11
CVE-2024-55591
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet9.694.1%KEV2025-01-14
CVE-2024-1709
Authentication bypass using an alternate path or channel
ConnectWise10.0100.0%KEV2024-02-21
CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
F59.896.5%KEV2023-10-26
CVE-2020-10148
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
SolarWinds9.892.0%KEV2020-12-29
CVE-2026-10523
-
ivanti9.953.1%2026-06-09

Frequently Asked Questions

What is CWE-288?→

CWE-288 is an authentication bypass where an alternate path or channel reaches functionality that the primary path protects with authentication.

How is CWE-288 prevented?→

MITRE recommends funneling all access through a single choke point and checking permissions on every access.

How many exploited vulnerabilities are classified as CWE-288?→

This database lists 16 CVE records mapped to CWE-288 by their CVE Numbering Authority. 15 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 5 to known ransomware campaigns. Examples include CVE-2026-18556, CVE-2026-18577, CVE-2026-1603.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.