CWE-424: Improper Protection of Alternate Path

low-risk

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Abstraction: Class

Common Consequences

Access Control Bypass Protection Mechanism

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2025-48827 10.0 77.6%
CVE-2025-48828 9.0 73.7%
CVE-2024-58136 9.0 57.5% Y
CVE-2024-3927 5.3 0.5%
CVE-2019-18997 4.3 0.4%
CVE-2021-3793 6.5 0.3%
CVE-2023-20272 6.7 0.3%
CVE-2025-46654 4.9 0.2%
CVE-2025-46655 4.9 0.2%
CVE-2019-18996 7.1 0.1%
9
/ 100
low-risk
Active Threat 8/50 · Minimal
Exploit Availability 1/50 · Minimal