Back to Labs
Weakness (CWE)

CWE-288

Authentication Bypass Using an Alternate Path or Channel

About

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Common consequences

  • Access Control → Bypass Protection Mechanism

Mitigations

  • Architecture and Design: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

CVEs with this weakness

Frequently asked questions

What is CWE-288?

The product requires authentication, but the product has an alternate path or channel that does not require authentication. Common consequences Access Control → Bypass Protection Mechanism Mitigations Architecture and Design: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

Which platforms does CWE-288 affect?

CWE-288 has been observed on: Not Technology-Specific, Web Based.

How many CVEs does Rainforest track for CWE-288?

Rainforest Labs currently tracks 2 published CVEs mapped to CWE-288. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.