Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-288'

View all threats tagged with 'cwe-288'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-288

Threats Tagged 'cwe-288'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-10523: CWE-288 Authentication bypass using an alternate path or channel in ivanti SentryCVE-2026-10523
0

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Join the discussion
CVE-2026-5415: CWE-288 Authentication Bypass Using an Alternate Path or Channel in webfactory Advanced Google reCAPTCHACVE-2026-5415
0

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a nonce check (check_ajax_referer) for security without performing any capability check, combined with the create_temporary_link tool allowing the generation of passwordless login links for arbitrary users, and the handle_temporary_links() function authenticating visitors via these links without any additional authorization validation. The required nonce is exposed to all authenticated backend users (including Subscribers) via wp_localize_script() on all non-settings admin pages when the plugin's welcome pointer has not been dismissed. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass normal authentication and log in as any user, including Administrators, resulting in complete account takeover.

Join the discussion
CVE-2024-6684: CWE-288 Authentication Bypass Using an Alternate Path or Channel in GST Electronics inohom Nova Panel N7CVE-2024-6684
0

Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not supported.

Join the discussion
CVE-2024-5620: CWE-288 Authentication Bypass Using an Alternate Path or Channel in PruvaSoft Informatics Apinizer Management ConsoleCVE-2024-5620
0

Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass. This issue affects Apinizer Management Console: before 2024.05.1.

Join the discussion
CVE-2026-42654: CWE-288 Authentication Bypass Using an Alternate Path or Channel in WP Swings Wallet System for WooCommerceCVE-2026-42654
0

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.

Join the discussion
CVE-2026-40780: CWE-288 Authentication Bypass Using an Alternate Path or Channel in Liquid Web / StellarWP BookItCVE-2026-40780
0

Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1.

Join the discussion
CVE-2026-45577: CWE-288: Authentication Bypass Using an Alternate Path or Channel in markmhendrickson neotomaCVE-2026-45577
0

Neotoma versions from 0.6.0 up to but not including 0.11.1 have an authentication bypass vulnerability. The application can mistakenly treat public reverse-proxied requests received over a loopback socket without a Bearer token as local requests. This causes the REST authentication middleware to resolve unauthenticated requests as the local development user, exposing the Inspector and related API without requiring credentials. This issue is fixed in version 0.11.1.

Join the discussion
CVE-2025-41273: CWE-288 Authentication Bypass Using an Alternate Path or Channel in Waterfall WF-500CVE-2025-41273
0

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user.

Join the discussion
CVE-2026-8697: CWE-288 Authentication bypass using an alternate path or channel in TP-Link Systems Inc. Archer C64 v1.0CVE-2026-8697
0

CVE-2026-8697 is a high-severity vulnerability in TP-Link Archer C64 v1.0 where the debug SSH service does not enforce authentication rate-limiting. This allows an attacker with adjacent network access to perform unlimited brute-force attempts using the same credentials as the web interface. Successful exploitation can lead to administrative access, compromising the device's confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-8990: CWE-288 Authentication Bypass Using an Alternate Path or Channel in View Concept KidsviewCVE-2026-8990
0

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3

Join the discussion

Showing 1 to 10 of 200 results

Filters:Tag: cwe-288
Page 1 of 20
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses