What is CWE-288?
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
CWE-288 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based.
Source: MITRE CWE (CWE-288 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Bypass Protection Mechanism
Source: MITRE CWE, common consequences.
How CWE-288 is exploited in the wild
Threadlinqs maps 18 CVEs to CWE-288, published between 2023-09-06 and 2026-09-08. 12 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 6 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 9 critical, 3 high, 2 medium. The highest EPSS score in the set is 96.5% (CVE-2023-46747), the modelled probability of exploitation in the next 30 days. 51 tracked threats reference CWE-288 directly or through a CVE it covers; the most recent is “Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)” (2026-09-23). Affected products concentrate in Cisco (2), Fortinet (2), Ivanti (2), among 13 vendors in total.
Vulnerabilities (CVEs)
All 18 CVEs mapped to CWE-288, CISA KEV first, then by CVSS score.
- CVE-2024-1709 — CISA KEV · CVSS 10 critical · EPSS 94.3% · published 2024-02-21
- CVE-2026-20079 — CISA KEV · CVSS 10 critical · EPSS 88.1% · published 2026-03-04
- CVE-2023-46747 — CISA KEV · CVSS 9.8 critical · EPSS 96.5% · published 2023-10-26
- CVE-2024-55591 — CISA KEV · CVSS 9.8 critical · EPSS 94.1% · published 2025-01-14
- CVE-2024-27198 — CISA KEV · CVSS 9.8 critical · EPSS 93.0% · published 2024-03-04
- CVE-2026-23760 — CISA KEV · CVSS 9.8 critical · EPSS 78.7% · published 2026-01-22
- CVE-2026-19490 — CISA KEV · CVSS 9.8 critical · EPSS 7.0% · published 2026-08-19
- CVE-2026-24858 — CISA KEV · CVSS 9.8 critical · EPSS 2.2% · published 2026-01-27
- CVE-2026-1603 — CISA KEV · CVSS 8.6 high · EPSS 54.8% · published 2026-02-10
- CVE-2025-4427 — CISA KEV · CVSS 5.3 medium · EPSS 91.5% · published 2025-05-13
- CVE-2023-20269 — CISA KEV · CVSS 5 medium · EPSS 0.8% · published 2023-09-06
- CVE-2026-18577 — CISA KEV · EPSS 1.4% · published 2026-08-02
- CVE-2026-57807 — CVSS 9.8 critical · EPSS 0.4% · published 2026-07-10
- CVE-2025-32976 — CVSS 8.8 high · EPSS 0.1% · published 2025-06-24
- CVE-2026-78259 — CVSS 7.3 high · EPSS 0.2% · published 2026-08-24
- CVE-2026-86084 — EPSS 0.3% · published 2026-09-08
- CVE-2026-18556 — EPSS 0.2% · published 2026-08-01
- CVE-2026-18574 — published 2026-08-03
Affected vendors
Threat activity
51 tracked threats cite CWE-288; the 25 most recent are listed.
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced OperatorsMEDIUM
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)CRITICAL
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone ExfiltrationCRITICAL
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with Accompanying CVE-2026-19489 Memory Overflow (CVSS 8.8)CRITICAL
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin Access and Cloudflare Tunnel PersistenceHIGH
- Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)HIGH
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and DjangoCRITICAL
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin TakeoverCRITICAL
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management ServerCRITICAL
- PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague / pam_exec Technique LineageHIGH
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVCRITICAL
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)HIGH
- Critical Authentication Bypass in WordPress OAuth Single Sign-On (SSO) Plugin by miniOrange (CVE-2026-57807)CRITICAL
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)CRITICAL
- StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt StrikeHIGH
- python.org Release Management API Authentication Bypass (Patched, No Exploitation Confirmed)HIGH
- CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)CRITICAL
Mitigations
- Architecture and Design: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.
Source: MITRE CWE, potential mitigations.