The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Volume of CVEs assigned to CWE-288 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
607 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27198CRITICAL In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | Mar 4, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-1709CRITICAL ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
vulnerability, which may allow an attacker direct access to | Feb 21, 2024 | 10.0 | 99 | YES | YES |
CVE-2023-42793CRITICAL In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | Sep 19, 2023 | 9.8 | 99 | YES | YES |
CVE-2026-23760CRITICAL SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous | Jan 22, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-57819CRITICAL FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenti | Aug 28, 2025 | 9.8 | 98 | YES | YES |
CVE-2025-4427HIGH An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the | May 13, 2025 | 7.5 | 98 | YES | YES |
CVE-2024-55591CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7 | Jan 14, 2025 | 9.8 | 98 | YES | YES |
CVE-2023-46747CRITICAL Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre | Oct 26, 2023 | 9.8 | 98 | YES | YES |
CVE-2026-1603HIGH An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. | Feb 10, 2026 | 7.5 | 97 | YES | YES |
CVE-2025-2747CRITICAL An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A | Mar 24, 2025 | 9.8 | 97 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.