CWE-288
Authentication Bypass Using an Alternate Path or Channel
About
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Common consequences
- Access Control → Bypass Protection Mechanism
Mitigations
- Architecture and Design: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
CVEs with this weakness
Frequently asked questions
What is CWE-288?
The product requires authentication, but the product has an alternate path or channel that does not require authentication. Common consequences Access Control → Bypass Protection Mechanism Mitigations Architecture and Design: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Which platforms does CWE-288 affect?
CWE-288 has been observed on: Not Technology-Specific, Web Based.
How many CVEs does Rainforest track for CWE-288?
Rainforest Labs currently tracks 2 published CVEs mapped to CWE-288. They are listed on this page.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
