> For the complete documentation index, see [llms.txt](https://wiki.smhuda.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.smhuda.com/vulnerability-wiki/application-level/authentication/authentication-bypass.md).

# Authentication Bypass

### Severity:&#x20;

<mark style="color:orange;">**Medium**</mark>

### How to test:

* Check if post-authentication URLs are directly accessible without any authentication cookies or relevant headers.
* n case the URL is guessable or accessible without auth, it can lead to an account takeover.
