CWE-289 · 42 records
Authentication Bypass by Alternate Name
CVEs in this class
42 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2024-56511Proof of concept | DataEase has an unauthorized vulnerabilitydataease · dataease · CWE-289 | Critical9.3 | — | 44.5% | Jan 10, 2025 |
44Plan | CVE-2021-34746No exploit | Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerabilitycisco · enterprise nfv infrastructure software · CWE-289 | Critical9.8 | — | 17.7% | Sep 1, 2021 |
39Monitor | CVE-2023-1803No exploit | Authentication Bypass in Redline Routerredline · router firmware · CWE-289 | Critical9.8 | — | 0.8% | Apr 14, 2023 |
39Monitor | CVE-2026-8457No exploit | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWTwpweb · woocommerce - social login · CWE-289 | Critical9.8 | — | 0.7% | Aug 1, 2026 |
39Monitor | CVE-2026-9701No exploit | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalationjoe007 · eventer · CWE-289 | Critical9.8 | — | 0.5% | Jul 8, 2026 |
39Monitor | CVE-2025-13613No exploit | Elated Membership <= 1.2 - Authentication Bypass via Social Loginelated themes · elated membership · CWE-289 | Critical9.8 | — | 0.5% | Dec 9, 2025 |
39Monitor | CVE-2026-15980No exploit | MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Tokentangiblewp · myhome core · CWE-289 | Critical9.8 | — | 0.5% | Aug 30, 2026 |
39Monitor | CVE-2026-76183No exploit | Apache Tomcat: Bypass of security constraints for WebSocket endpointsapache software foundation · apache tomcat · CWE-289 | Critical9.8 | — | 0.4% | Sep 23, 2026 |
38Monitor | CVE-2025-29266No exploit | Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is runraid · unraid · CWE-289 | Critical9.6 | — | 0.4% | Mar 31, 2025 |
37Monitor | CVE-2025-55130Proof of concept | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativnodejs · node.js · CWE-289 | Critical9.1 | — | 1.7% | Jan 20, 2026 |
36Monitor | CVE-2017-16590No exploit | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.69netgain-systems · enterprise manager · CWE-289 | High8.8 | — | 3.3% | Jan 22, 2018 |
36Monitor | CVE-2026-50627No exploit | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validatorapache · cxf · CWE-289 | Critical9.1 | — | 0.8% | Jun 12, 2026 |
35Monitor | CVE-2023-20046No exploit | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevatcisco · staros · CWE-289 | High8.8 | — | 0.9% | May 9, 2023 |
33Monitor | CVE-2026-32036No exploit | OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channelsopenclaw · openclaw · CWE-289 | High8.3 | — | 0.7% | Mar 19, 2026 |
32Monitor | CVE-2023-38487No exploit | HedgeDoc API allows to hide existing noteshedgedoc · hedgedoc · CWE-289 | High8.2 | — | 0.8% | Aug 4, 2023 |
32Monitor | CVE-2026-56091No exploit | Apache Shiro: Authentication bypass in Guice-Web integrationapache software foundation · apache shiro · CWE-289 | High8.2 | — | 0.7% | Jun 25, 2026 |
32Monitor | CVE-2026-24058No exploit | Soft Serve has Critical Authentication Bypasscharm · soft serve · CWE-289 | High8.1 | — | 0.6% | Jan 22, 2026 |
32Monitor | CVE-2026-15985No exploit | Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Loginradiustheme · classified listing - mobile number verification · CWE-289 | High8.1 | — | 0.3% | Aug 26, 2026 |
32Monitor | CVE-2026-12101No exploit | Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Accessibm · verify identity access · CWE-289 | High8.1 | — | 0.3% | Sep 15, 2026 |
31Monitor | CVE-2025-64343No exploit | (conda) Constructor: Excessive permissions during and after installationconda · constructor · CWE-289 | High7.8 | — | 0.1% | Nov 7, 2025 |
30Monitor | CVE-2023-41890No exploit | Sustainsys.Saml2 Insufficient Identity Provider Issuer Validationsustainsys · saml2 · CWE-289 | High7.5 | — | 0.8% | Sep 19, 2023 |
30Monitor | CVE-2023-3263No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the dataprobe · iboot-pdu4a-c10 firmware · CWE-289 | High7.5 | — | 0.7% | Aug 14, 2023 |
30Monitor | CVE-2026-10842No exploit | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerabilityibm · websphere application server · CWE-289 | High7.5 | — | 0.5% | Jul 30, 2026 |
30Monitor | CVE-2024-2098No exploit | Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibraryw3eden · download manager · CWE-289 | High7.5 | — | 0.5% | Jun 13, 2024 |
30Monitor | CVE-2025-41248No exploit | CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized typesvmware · spring security · CWE-289 | High7.5 | — | 0.4% | Sep 16, 2025 |
- CVE-2024-5651150Plan
DataEase has an unauthorized vulnerability
CriticalCVSS 9.3Proof of conceptEPSS 44%dataease · dataeaseJan 10, 2025
- CVE-2021-3474644Plan
Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
CriticalCVSS 9.8No exploitEPSS 18%cisco · enterprise nfv infrastructure softwareSep 1, 2021
- CVE-2023-180339Monitor
Authentication Bypass in Redline Router
CriticalCVSS 9.8No exploitEPSS 1%redline · router firmwareApr 14, 2023
- CVE-2026-845739Monitor
WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
CriticalCVSS 9.8No exploitEPSS 1%wpweb · woocommerce - social loginAug 1, 2026
- CVE-2026-970139Monitor
Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
CriticalCVSS 9.8No exploitEPSS 0%joe007 · eventerJul 8, 2026
- CVE-2025-1361339Monitor
Elated Membership <= 1.2 - Authentication Bypass via Social Login
CriticalCVSS 9.8No exploitEPSS 0%elated themes · elated membershipDec 9, 2025
- CVE-2026-1598039Monitor
MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
CriticalCVSS 9.8No exploitEPSS 0%tangiblewp · myhome coreAug 30, 2026
- CVE-2026-7618339Monitor
Apache Tomcat: Bypass of security constraints for WebSocket endpoints
CriticalCVSS 9.8No exploitEPSS 0%apache software foundation · apache tomcatSep 23, 2026
- CVE-2025-2926638Monitor
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is r
CriticalCVSS 9.6No exploitEPSS 0%unraid · unraidMar 31, 2025
- CVE-2025-5513037Monitor
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativ
CriticalCVSS 9.1Proof of conceptEPSS 2%nodejs · node.jsJan 20, 2026
- CVE-2017-1659036Monitor
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.69
HighCVSS 8.8No exploitEPSS 3%netgain-systems · enterprise managerJan 22, 2018
- CVE-2026-5062736Monitor
Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
CriticalCVSS 9.1No exploitEPSS 1%apache · cxfJun 12, 2026
- CVE-2023-2004635Monitor
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevat
HighCVSS 8.8No exploitEPSS 1%cisco · starosMay 9, 2023
- CVE-2026-3203633Monitor
OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels
HighCVSS 8.3No exploitEPSS 1%openclaw · openclawMar 19, 2026
- CVE-2023-3848732Monitor
HedgeDoc API allows to hide existing notes
HighCVSS 8.2No exploitEPSS 1%hedgedoc · hedgedocAug 4, 2023
- CVE-2026-5609132Monitor
Apache Shiro: Authentication bypass in Guice-Web integration
HighCVSS 8.2No exploitEPSS 1%apache software foundation · apache shiroJun 25, 2026
- CVE-2026-2405832Monitor
Soft Serve has Critical Authentication Bypass
HighCVSS 8.1No exploitEPSS 1%charm · soft serveJan 22, 2026
- CVE-2026-1598532Monitor
Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login
HighCVSS 8.1No exploitEPSS 0%radiustheme · classified listing - mobile number verificationAug 26, 2026
- CVE-2026-1210132Monitor
Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
HighCVSS 8.1No exploitEPSS 0%ibm · verify identity accessSep 15, 2026
- CVE-2025-6434331Monitor
(conda) Constructor: Excessive permissions during and after installation
HighCVSS 7.8No exploitEPSS 0%conda · constructorNov 7, 2025
- CVE-2023-4189030Monitor
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
HighCVSS 7.5No exploitEPSS 1%sustainsys · saml2Sep 19, 2023
- CVE-2023-326330Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the
HighCVSS 7.5No exploitEPSS 1%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2026-1084230Monitor
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
HighCVSS 7.5No exploitEPSS 1%ibm · websphere application serverJul 30, 2026
- CVE-2024-209830Monitor
Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
HighCVSS 7.5No exploitEPSS 0%w3eden · download managerJun 13, 2024
- CVE-2025-4124830Monitor
CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized types
HighCVSS 7.5No exploitEPSS 0%vmware · spring securitySep 16, 2025