Cyber Posture

CWE · MITRE source

CWE-288Authentication Bypass Using an Alternate Path or Channel

Abstraction: Base · CVEs in our corpus: 522

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (6)AI

Control Title Family Why it addresses this CWE
IA-10Adaptive AuthenticationIAAdaptive requirements can apply across access paths, reducing the ability to bypass authentication via alternate channels or paths.
IA-13Identity Providers and Authorization ServersIACentralized IdPs close alternate authentication paths that enable bypass.
IA-8Identification and Authentication (Non-organizational Users)IAEnforces authentication for non-organizational users, making it harder to bypass via alternate paths or channels.
AC-17Remote AccessACAuthorizing remote access reduces the ability to bypass authentication via unauthorized alternate remote channels.
AC-9Previous Logon NotificationACUsers can identify logons via alternate paths or channels by reviewing the previous logon time.
SC-11Trusted PathSCRequires authentication to occur exclusively over the isolated trusted path, directly preventing bypass via alternate or untrusted channels.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-1709 KEV9.710.00.94322024-02-21
CVE-2020-10148 KEV9.69.80.94352020-12-29
CVE-2023-46747 KEV9.69.80.94442023-10-26
CVE-2024-55591 KEV9.69.80.94062025-01-14
CVE-2023-42793 KEV9.59.80.92912023-09-19
CVE-2024-27198 KEV9.59.80.93052024-03-04
CVE-2025-2747 KEV9.49.80.91262025-03-24
CVE-2025-2746 KEV9.39.80.89732025-03-24
CVE-2026-23760 KEV8.89.80.79942026-01-22
CVE-2025-57819 KEV8.69.80.76732025-08-28
CVE-2025-4427 KEV8.55.30.91262025-05-13
CVE-2025-34026 KEV7.87.50.71082025-05-21
CVE-2024-109247.69.80.93892024-11-15
CVE-2023-29867.59.80.91712023-06-08
CVE-2024-99897.59.80.92612024-10-29
CVE-2023-27327.49.80.90332023-05-25
CVE-2020-278667.28.80.90782021-02-12
CVE-2026-1603 KEV7.18.60.55872026-02-10
CVE-2024-504776.99.80.82232024-10-28
CVE-2022-253696.89.80.80142026-01-23
CVE-2023-24376.69.80.76792023-11-22
CVE-2024-100816.410.00.73912024-11-06
CVE-2024-239176.39.80.72922024-02-06
CVE-2023-29826.29.80.70122023-06-29
CVE-2024-73146.29.80.70102024-08-02