Threadlinqs IntelligenceStart free

Weakness · BaseCWE-288

CWE-288: Authentication Bypass Using an Alternate Path or Channel

KEV-linkedBase

As of 2026-10-05, CWE-288 (Authentication Bypass Using an Alternate Path or Channel) underlies 18 CVEs tracked by Threadlinqs, 12 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 51 tracked threats.

CVEs
18Mapped to CWE-288
CISA KEV
12Exploited in the wild
Critical
9CVSS v3 critical CVEs
Threats
51Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-288?

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

CWE-288 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based.

Source: MITRE CWE (CWE-288 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism

Source: MITRE CWE, common consequences.

How CWE-288 is exploited in the wild

Threadlinqs maps 18 CVEs to CWE-288, published between 2023-09-06 and 2026-09-08. 12 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 6 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 9 critical, 3 high, 2 medium. The highest EPSS score in the set is 96.5% (CVE-2023-46747), the modelled probability of exploitation in the next 30 days. 51 tracked threats reference CWE-288 directly or through a CVE it covers; the most recent is “Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)” (2026-09-23). Affected products concentrate in Cisco (2), Fortinet (2), Ivanti (2), among 13 vendors in total.

Vulnerabilities (CVEs)

All 18 CVEs mapped to CWE-288, CISA KEV first, then by CVSS score.

  • CVE-2024-1709 — CISA KEV · CVSS 10 critical · EPSS 94.3% · published 2024-02-21
  • CVE-2026-20079 — CISA KEV · CVSS 10 critical · EPSS 88.1% · published 2026-03-04
  • CVE-2023-46747 — CISA KEV · CVSS 9.8 critical · EPSS 96.5% · published 2023-10-26
  • CVE-2024-55591 — CISA KEV · CVSS 9.8 critical · EPSS 94.1% · published 2025-01-14
  • CVE-2024-27198 — CISA KEV · CVSS 9.8 critical · EPSS 93.0% · published 2024-03-04
  • CVE-2026-23760 — CISA KEV · CVSS 9.8 critical · EPSS 78.7% · published 2026-01-22
  • CVE-2026-19490 — CISA KEV · CVSS 9.8 critical · EPSS 7.0% · published 2026-08-19
  • CVE-2026-24858 — CISA KEV · CVSS 9.8 critical · EPSS 2.2% · published 2026-01-27
  • CVE-2026-1603 — CISA KEV · CVSS 8.6 high · EPSS 54.8% · published 2026-02-10
  • CVE-2025-4427 — CISA KEV · CVSS 5.3 medium · EPSS 91.5% · published 2025-05-13
  • CVE-2023-20269 — CISA KEV · CVSS 5 medium · EPSS 0.8% · published 2023-09-06
  • CVE-2026-18577 — CISA KEV · EPSS 1.4% · published 2026-08-02
  • CVE-2026-57807 — CVSS 9.8 critical · EPSS 0.4% · published 2026-07-10
  • CVE-2025-32976 — CVSS 8.8 high · EPSS 0.1% · published 2025-06-24
  • CVE-2026-78259 — CVSS 7.3 high · EPSS 0.2% · published 2026-08-24
  • CVE-2026-86084 — EPSS 0.3% · published 2026-09-08
  • CVE-2026-18556 — EPSS 0.2% · published 2026-08-01
  • CVE-2026-18574 — published 2026-08-03

Affected vendors

Threat activity

51 tracked threats cite CWE-288; the 25 most recent are listed.

Mitigations

  • Architecture and Design: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

Source: MITRE CWE, potential mitigations.