CWE-289


Authentication Bypass by Alternate Name

The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.


We have discovered 24,892 live websites that are affected by CWE-289.

Contact us to get more info









CVEs

  • Count - 6



Website Distribution by Country

Number of websites using CWE-289
United States5,593 websites



Switzerland2,425 websites
Italy1,791 websites
Japan1,709 websites
Germany1,701 websites
Korea, South1,642 websites
Canada999 websites
France861 websites
Spain763 websites

Website Distribution by TLD

Number of websites using CWE-289
.com8,747 websites
.ch2,329 websites
.org1,781 websites
.it1,401 websites
.de1,072 websites
.net972 websites
.ca435 websites
.es407 websites
.jp400 websites
.fr381 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-289
DiscoveredCVEDescriptionWebsites
Aug, 2026CVE-2026-32639 Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads1
Aug, 2026CVE-2026-8457 WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT510
Jul, 2026CVE-2026-10842 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability5
Jul, 2026CVE-2026-9701 Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation231
Jun, 2026CVE-2026-56091 Apache Shiro: Authentication bypass in Guice-Web integration15,112
Jun, 2024CVE-2024-2098 Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary9,036
List of the most common CVEs that are part of CWE-289
DiscoveredCVEDescriptionWebsites
Jun, 2026CVE-2026-56091 Apache Shiro: Authentication bypass in Guice-Web integration15,112
Jun, 2024CVE-2024-2098 Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary9,036
Aug, 2026CVE-2026-8457 WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT510
Jul, 2026CVE-2026-9701 Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation231
Jul, 2026CVE-2026-10842 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability5
Aug, 2026CVE-2026-32639 Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads1

Websites affected by CWE-289

Top websites that are affected by CWE-289. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.***.org United States*,***
********.org Germany*,***
****************.ch Switzerland*,***
****.edu United States**,***
***********.com Netherlands**,***
********.********.edu United States**,***
****.********.org France**,***
****.****.***.edu United States**,***
****.****.edu United States**,***
*******.org United States**,***
See full domain list