Authentication Bypass Using an Alternate Path (CWE-288)
CWE-288 describes a product that requires authentication but also offers an alternate path or channel that skips it. The main entry point is protected while another route to the same resource is not. MITRE notes an overlap with unprotected alternate channels.
About CWE-288
The direct consequence is bypass of the protection mechanism, so the access control the main path enforces does not apply.
Mitigations
- +Route all access through a single choke point so there is one path to each resource.
- +Perform a permission check on every access to a resource, regardless of how the request arrived.
- +Inventory all channels and interfaces, including those assumed private, and apply authentication to each.
CWE-288 Vulnerabilities
16 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-18556 | Unauthenticated administrative account takeover | N-able | 8.2 | 7.9% | KEV | 2026-08-01 |
| CVE-2026-18577 | Incomplete patch leads to administrative account takeover | N-able | 8.2 | 14.6% | KEV | 2026-08-02 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | Ivanti | 8.6 | 88.3% | KEV | 2026-02-10 |
| CVE-2026-24858 | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Fortinet | 9.4 | 85.8% | KEV | 2026-01-27 |
| CVE-2026-23760 | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API | SmarterTools | 9.3 | 96.5% | KEV | 2026-01-22 |
| CVE-2025-34026 | Versa Concerto Actuator Authentication Bypass Information Leak | Versa | 9.2 | 81.9% | KEV | 2025-05-21 |
| CVE-2025-2747 | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass | Kentico | 9.8 | 97.2% | KEV | 2025-03-24 |
| CVE-2025-2746 | Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass | Kentico | 9.8 | 73.0% | KEV | 2025-03-24 |
| CVE-2025-57819 | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE | FreePBX | 10.0 | 86.3% | KEV | 2025-08-28 |
| CVE-2025-4427 | Authentication Bypass | Ivanti | 5.3 | 99.9% | KEV | 2025-05-13 |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Fortinet | 8.1 | 7.2% | KEV | 2025-02-11 |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Fortinet | 9.6 | 94.1% | KEV | 2025-01-14 |
| CVE-2024-1709 | Authentication bypass using an alternate path or channel | ConnectWise | 10.0 | 100.0% | KEV | 2024-02-21 |
| CVE-2023-46747 | BIG-IP Configuration utility unauthenticated remote code execution vulnerability | F5 | 9.8 | 96.5% | KEV | 2023-10-26 |
| CVE-2020-10148 | SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands | SolarWinds | 9.8 | 92.0% | KEV | 2020-12-29 |
| CVE-2026-10523 | - | ivanti | 9.9 | 53.1% | 2026-06-09 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-288?→
CWE-288 is an authentication bypass where an alternate path or channel reaches functionality that the primary path protects with authentication.
How is CWE-288 prevented?→
MITRE recommends funneling all access through a single choke point and checking permissions on every access.
How many exploited vulnerabilities are classified as CWE-288?→
This database lists 16 CVE records mapped to CWE-288 by their CVE Numbering Authority. 15 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 5 to known ransomware campaigns. Examples include CVE-2026-18556, CVE-2026-18577, CVE-2026-1603.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.