On this page

CWE-288: Authentication Bypass Using an Alternate Path or Channel

Weakness Summary

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

  • Canonical source: MITRE CWE-288 (opens in a new tab)
  • Published Atomicorp CVE observations: 10
  • Distinct affected products in those observations: 10
  • Active Atomicorp rules associated with this weakness: 30

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2024-10081CodeChecker <= 6.24.1 - Authentication BypasscodecheckerAttack Blocked by Atomicorp392301
CVE-2025-57819FreePBX - Remote Code ExecutionfreepbxAttack Blocked by Atomicorp340157 , 341245 , 344365 , 344370 , 360147 , 360148
CVE-2026-53576Kestra <= 1.3.20 - Remote Code ExecutionkestraAttack Blocked by Atomicorp391213
CVE-2020-10148SolarWinds Orion API - Auth Bypassorion platformAttack Blocked by Atomicorp390709
CVE-2023-2734MStore API <= 3.9.1 - Authentication Bypassmstore apiAttack Blocked by Atomicorp330791 , 340152
CVE-2023-46747F5 BIG-IP - Unauthenticated RCE via AJP Smugglingbig-ip access policy managerAttack Blocked by Atomicorp390626 , 392767
CVE-2024-7314AJ-Report < 1.4.1 - Remote Code ExecutionreportAttack Blocked by Atomicorp337209 , 337211 , 380026
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXAAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2024-50334Scoold < 1.64.0 - Authentication BypassscooldAttack Blocked by Atomicorp391213
CVE-2025-4427Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Executionendpoint manager mobileAttack Blocked by Atomicorp337210 , 340087 , 340095 , 380026 , 393655

Associated Atomicorp WAF Rules

RuleStatusBehavior
330791Activedisruptive (deny)
337209Activedisruptive (deny)
337210Activedisruptive (deny)
337211Activedisruptive (deny)
340014Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340087Activedisruptive (deny)
340095Activedisruptive (deny)
340152Activedisruptive (deny)
340157Activedisruptive (deny)
340193Activedisruptive (deny)
341245Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
347009Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
380026Activedisruptive (deny)
390626Activedisruptive (deny)
390709Activedisruptive (deny)
391213Activedisruptive (deny)
392301Activedisruptive (deny)
392767Activedisruptive (deny)
393655Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-127 (opens in a new tab) , CAPEC-665 (opens in a new tab)