Common Weakness Enumeration

    CWE Definition / CWE-288

    CWE-288: Authentication Bypass Using an Alternate Path or Channel

    The product requires authentication, but the product has an alternate path or channel that does not require authentication.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-306: Missing Authentication for Critical Function

    CWE-284: Improper Access Control

    CWE-420: Unprotected Alternate Channel