CWE-424

Improper Protection of Alternate Path
AI Translation Available

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Status
draft
Abstraction
class
Not Technology-Specific Web Based

Common Consequences

access control
Impacts
bypass protection mechanism gain privileges or assume identity

Potential Mitigations

Phases:
architecture and design
Descriptions:
• Deploy different layers of protection to implement security in depth.