# CWE-288: Authentication Bypass Using an Alternate Path or Channel

**KEV-linked**

> As of 2026-10-05, CWE-288 (Authentication Bypass Using an Alternate Path or Channel) underlies 18 CVEs tracked by Threadlinqs, 12 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 51 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-288?

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

CWE-288 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/288.html) (CWE-288 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism

_Source: MITRE CWE, common consequences._

## How CWE-288 is exploited in the wild

Threadlinqs maps 18 CVEs to CWE-288, published between 2023-09-06 and 2026-09-08. 12 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 6 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 9 critical, 3 high, 2 medium. The highest EPSS score in the set is 96.5% (CVE-2023-46747), the modelled probability of exploitation in the next 30 days. 51 tracked threats reference CWE-288 directly or through a CVE it covers; the most recent is “Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)” (2026-09-23). Affected products concentrate in Cisco (2), Fortinet (2), Ivanti (2), among 13 vendors in total.

## Vulnerabilities (CVEs)

All 18 CVEs mapped to CWE-288, CISA KEV first, then by CVSS score.

- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709) — CISA KEV · CVSS 10 critical · EPSS 94.3% · published 2024-02-21
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079) — CISA KEV · CVSS 10 critical · EPSS 88.1% · published 2026-03-04
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747) — CISA KEV · CVSS 9.8 critical · EPSS 96.5% · published 2023-10-26
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591) — CISA KEV · CVSS 9.8 critical · EPSS 94.1% · published 2025-01-14
- [CVE-2024-27198](https://intel.threadlinqs.com/cve/CVE-2024-27198) — CISA KEV · CVSS 9.8 critical · EPSS 93.0% · published 2024-03-04
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760) — CISA KEV · CVSS 9.8 critical · EPSS 78.7% · published 2026-01-22
- [CVE-2026-19490](https://intel.threadlinqs.com/cve/CVE-2026-19490) — CISA KEV · CVSS 9.8 critical · EPSS 7.0% · published 2026-08-19
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858) — CISA KEV · CVSS 9.8 critical · EPSS 2.2% · published 2026-01-27
- [CVE-2026-1603](https://intel.threadlinqs.com/cve/CVE-2026-1603) — CISA KEV · CVSS 8.6 high · EPSS 54.8% · published 2026-02-10
- [CVE-2025-4427](https://intel.threadlinqs.com/cve/CVE-2025-4427) — CISA KEV · CVSS 5.3 medium · EPSS 91.5% · published 2025-05-13
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269) — CISA KEV · CVSS 5 medium · EPSS 0.8% · published 2023-09-06
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577) — CISA KEV · EPSS 1.4% · published 2026-08-02
- [CVE-2026-57807](https://intel.threadlinqs.com/cve/CVE-2026-57807) — CVSS 9.8 critical · EPSS 0.4% · published 2026-07-10
- [CVE-2025-32976](https://intel.threadlinqs.com/cve/CVE-2025-32976) — CVSS 8.8 high · EPSS 0.1% · published 2025-06-24
- [CVE-2026-78259](https://intel.threadlinqs.com/cve/CVE-2026-78259) — CVSS 7.3 high · EPSS 0.2% · published 2026-08-24
- [CVE-2026-86084](https://intel.threadlinqs.com/cve/CVE-2026-86084) — EPSS 0.3% · published 2026-09-08
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556) — EPSS 0.2% · published 2026-08-01
- [CVE-2026-18574](https://intel.threadlinqs.com/cve/CVE-2026-18574) — published 2026-08-03

## Affected vendors

- [Cisco](https://intel.threadlinqs.com/vendors/cisco) — 2 CVEs
- [Fortinet](https://intel.threadlinqs.com/vendors/fortinet) — 2 CVEs
- [Ivanti](https://intel.threadlinqs.com/vendors/ivanti) — 2 CVEs
- [N-able](https://intel.threadlinqs.com/vendors/n-able) — 2 CVEs
- **Connectwise** — 1 CVE
- [F5](https://intel.threadlinqs.com/vendors/f5) — 1 CVE
- [Jetbrains](https://intel.threadlinqs.com/vendors/jetbrains) — 1 CVE
- [NetScaler](https://intel.threadlinqs.com/vendors/netscaler) — 1 CVE
- **Smartertools** — 1 CVE
- **WP Legal Pages** — 1 CVE
- [checkpoint](https://intel.threadlinqs.com/vendors/checkpoint) — 1 CVE
- **miniOrange Security Software Pvt Ltd.** — 1 CVE

## Threat activity

51 tracked threats cite CWE-288; the 25 most recent are listed.

- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL · 2026-09-23
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — MEDIUM · 2026-09-16
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)](https://intel.threadlinqs.com/threat/TL-2026-2396) — CRITICAL · 2026-09-08
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2271) — CRITICAL · 2026-09-01
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH · 2026-08-26
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH · 2026-08-23
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with Accompanying CVE-2026-19489 Memory Overflow (CVSS 8.8)](https://intel.threadlinqs.com/threat/TL-2026-2080) — CRITICAL · 2026-08-20
- [N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin Access and Cloudflare Tunnel Persistence](https://intel.threadlinqs.com/threat/TL-2026-1941) — HIGH · 2026-08-08
- [Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)](https://intel.threadlinqs.com/threat/TL-2026-1886) — HIGH · 2026-08-05
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django](https://intel.threadlinqs.com/threat/TL-2026-1891) — CRITICAL · 2026-08-05
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — CRITICAL · 2026-08-03
- [Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server](https://intel.threadlinqs.com/threat/TL-2026-1855) — CRITICAL · 2026-08-03
- [PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague / pam_exec Technique Lineage](https://intel.threadlinqs.com/threat/TL-2026-1772) — HIGH · 2026-07-30
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — CRITICAL · 2026-07-29
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — HIGH · 2026-07-27
- [CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1378) — CRITICAL · 2026-07-15
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH · 2026-07-14
- [UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)](https://intel.threadlinqs.com/threat/TL-2026-1257) — HIGH · 2026-07-13
- [Critical Authentication Bypass in WordPress OAuth Single Sign-On (SSO) Plugin by miniOrange (CVE-2026-57807)](https://intel.threadlinqs.com/threat/TL-2026-1262) — CRITICAL · 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)](https://intel.threadlinqs.com/threat/TL-2026-1232) — CRITICAL · 2026-07-11
- [StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1237) — HIGH · 2026-07-11
- [python.org Release Management API Authentication Bypass (Patched, No Exploitation Confirmed)](https://intel.threadlinqs.com/threat/TL-2026-1241) — HIGH · 2026-07-11
- [CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)](https://intel.threadlinqs.com/threat/TL-2026-1188) — CRITICAL · 2026-07-10

## Mitigations

- **Architecture and Design**: Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

_Source: MITRE CWE, potential mitigations._

## Related weaknesses

- [CWE-306 Missing Authentication for Critical Function](https://intel.threadlinqs.com/cwe/CWE-306)
- [CWE-284 Improper Access Control](https://intel.threadlinqs.com/cwe/CWE-284)
- [CWE-420](https://cwe.mitre.org/data/definitions/420.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-288
Source definition: https://cwe.mitre.org/data/definitions/288.html
Detection rules and IOCs for threats exploiting CWE-288 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
