BaseIncomplete

CWE-288Authentication Bypass Using an Alternate Path or Channel

Category: auth

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Common consequences· 1

  • Access Control — Bypass Protection Mechanism

Potential mitigations· 1

  • [Architecture and Design]Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

Related CAPEC attack patterns· 2

CAPEC-127CAPEC-665

References

  1. https://cwe.mitre.org/data/definitions/288.html

Exploits (incoming)2

TypeTargetConfidenceTier
AttackPatternDirectory Indexingcapec-127100%live
AttackPatternExploitation of Thunderbolt Protection Flawscapec-665100%live

Compliance frameworks addressing this (incoming)4

TypeTargetConfidenceTier
ComplianceControlpci_dss_v4-r8100%live
ComplianceControlnis2-art21j100%live
ComplianceControlowasp_api_top10-api02100%live
ComplianceControliso27001-a.8.5100%live

(incoming)144

TypeTargetConfidenceTier
VulnerabilityCVE-2025-0159cve-2025-01590%live
VulnerabilityCVE-2025-0181cve-2025-01810%live
VulnerabilityCVE-2025-0316cve-2025-03160%live
VulnerabilityCVE-2025-0364cve-2025-03640%live
VulnerabilityCVE-2025-0674cve-2025-06740%live
VulnerabilityCVE-2025-0749cve-2025-07490%live
VulnerabilityCVE-2025-10294cve-2025-102940%live
VulnerabilityCVE-2025-10484cve-2025-104840%live
VulnerabilityCVE-2025-10571cve-2025-105710%live
VulnerabilityCVE-2025-1061cve-2025-10610%live
VulnerabilityCVE-2025-10653cve-2025-106530%live
VulnerabilityCVE-2025-11522cve-2025-115220%live
VulnerabilityCVE-2025-11621cve-2025-116210%live
VulnerabilityCVE-2025-1283cve-2025-12830%live
VulnerabilityCVE-2025-13018cve-2025-130180%live
VulnerabilityCVE-2025-1313cve-2025-13130%live
VulnerabilityCVE-2025-1315cve-2025-13150%live
VulnerabilityCVE-2025-13539cve-2025-135390%live
VulnerabilityCVE-2025-15102cve-2025-151020%live
VulnerabilityCVE-2025-1515cve-2025-15150%live
VulnerabilityCVE-2025-1564cve-2025-15640%live
VulnerabilityCVE-2025-1638cve-2025-16380%live
VulnerabilityCVE-2025-1671cve-2025-16710%live
VulnerabilityCVE-2025-1717cve-2025-17170%live
VulnerabilityCVE-2025-1909cve-2025-19090%live
VulnerabilityCVE-2025-21589cve-2025-215890%live
VulnerabilityCVE-2025-22277cve-2025-222770%live
VulnerabilityCVE-2025-22462cve-2025-224620%live
VulnerabilityCVE-2025-23504cve-2025-235040%live
VulnerabilityCVE-2025-24000cve-2025-240000%live

Showing top 30 of 144 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Unprotected Primary Channel
CWE
Authentication Bypass by Alternate Name
CWE
Weak Authentication
CWE
Improper Protection of Alternate Path
CWE
Improper Access Control
CWE
Insufficiently Protected Credentials
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.