CWE-305Base2 in KEV

Authentication Bypass by Primary Weakness

Draft in the CWE catalog · 152 CVEs mapped

152
CVEs mapped
2
In KEV
7.8
Median CVSS
What it is

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Recent examples
none
CVE-2026-86207

CVE-2026-86207 - UNKNOWN Severity Vulnerability

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

no explanation yet
epss
9.8cvss
CVE-2026-81578

PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

KEV · due Sep 14CRITICALno explanation yet
2%
epss
none
CVE-2026-16895

CVE-2026-16895 - UNKNOWN Severity Vulnerability

A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-305
Abstraction
Base
Structure
Simple
Status
Draft