Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-288

Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

607
Assigned CVEs
67th
Commonality Rank
8.3
Avg CVSS
2.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-288 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 19, 2017
9 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

607 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-27198CRITICAL
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
Mar 4, 20249.899YESYES
CVE-2024-1709CRITICAL
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to
Feb 21, 202410.099YESYES
CVE-2023-42793CRITICAL
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Sep 19, 20239.899YESYES
CVE-2026-23760CRITICAL
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous
Jan 22, 20269.898YESYES
CVE-2025-57819CRITICAL
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenti
Aug 28, 20259.898YESYES
CVE-2025-4427HIGH
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the
May 13, 20257.598YESYES
CVE-2024-55591CRITICAL
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7
Jan 14, 20259.898YESYES
CVE-2023-46747CRITICAL
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre
Oct 26, 20239.898YESYES
CVE-2026-1603HIGH
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Feb 10, 20267.597YESYES
CVE-2025-2747CRITICAL
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A
Mar 24, 20259.897YESYES
View all 607 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
9%
16%
6.0-6.9
15%
26%
7.0-7.9
19%
11%
8.0-8.9
45%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
16 CVEs
2.6% of CVEs· 96th percentile
Metasploit
7 CVEs
1.2% of CVEs· 89th percentile
Nuclei
37 CVEs
6.1% of CVEs· 96th percentile
ExploitDB
9 CVEs
1.5% of CVEs· 85th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products