Compliance Node Overview
MITRE CAPEC-115 (Authentication Bypass) is an attack pattern in which an attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. This is distinct from credential theft - the attacker avoids authentication entirely rather than faking it. Typical severity: Medium. Maps to MITRE ATT&CK T1548 (Abuse Elevation Control Mechanism) and CWE-287 (Improper Authentication). The CAPEC page references OWASP Web Security Testing Guide for authentication-bypass testing methodology. Compliance: PCI DSS v4.0 Req 8, NIST SP 800-53 IA-2, ISO/IEC 27001 (secure authentication).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/115.html
SHA-256 integrity: e755409f014a62f240fa390224a907126d57456e7cb8a949de689ba62ef3eeba
Primary Citations — 8 traced to source
- MITRE CAPEC-115: Authentication Bypass (https://capec.mitre.org/data/definitions/115.html)
- CWE-287: Improper Authentication
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.