CWE-288: Authentication Bypass Using an Alternate Path or Channel

What is CWE-288?

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK7 — A07:2025 — Authentication Failures
RELATED CVES (365 DAYS)143
ABSTRACTIONBase

Vulnerabilities mapped to CWE-288

143 vulnerabilities150.9% increase year over year

Vulnerabilities in CISA KEV for CWE-288

5 vulnerabilities25% increase year over year

Official definition

ByMitre CWE

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Characteristics

Modes of introduction

  • Architecture and Design: COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.
  • Architecture and Design: This is often seen in web applications that assume that access to a particular CGI program can only be obtained through a "front" screen, when the supporting programs are directly accessible. But this problem is not just in web apps.

Common consequences

ImpactScopeExplanation
Bypass Protection MechanismAccess Control—

Risk mitigations

  1. Architecture and DesignFunnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

Representative vulnerabilities

Sources (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan