CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
2,826 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 42 of 57
- CVE-2026-2065MEDIUMCVSS 8.8EG 6.32026-02-06
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. …
- CVE-2026-20781CRITICALCVSS 9.8EG 9.82026-02-27
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint …
- CVE-2026-20803HIGHCVSS 7.2EG 7.22026-01-13
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20995MEDIUMCVSS 5.3EG 5.32026-03-16
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
- CVE-2026-21445CRITICALCVSS 9.1EG 9.12026-01-02
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to acce…
- CVE-2026-21446CRITICALCVSS 9.8EG 9.82026-01-02
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessi…
- CVE-2026-2165HIGHCVSS 9.8EG 7.32026-02-08
A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument em…
- CVE-2026-21767MEDIUMCVSS 4.0EG 4.02026-04-02
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication.
- CVE-2026-21992CRITICALCVSS 9.8EG 9.82026-03-20
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that…
- CVE-2026-22096CRITICALCVSS 9.3EG 9.32026-07-13
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.
- CVE-2026-22174MEDIUMCVSS 6.8EG 6.82026-03-18
OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback po…
- CVE-2026-22192CRITICALCVSS 9.9EG 9.92026-03-13
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify clie…
- CVE-2026-22207CRITICALCVSS 9.8EG 9.82026-02-26
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send r…
- CVE-2026-22238CRITICALCVSS 9.8EG 9.82026-01-14
The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to c…
- CVE-2026-2234CRITICALCVSS 9.1EG 9.12026-02-09
C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content.
- CVE-2026-2248CRITICALCVSS 9.8EG 9.82026-02-11
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with…
- CVE-2026-2249CRITICALCVSS 9.8EG 9.82026-02-11
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with…
- CVE-2026-22552CRITICALCVSS 9.8EG 9.42026-03-06
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint usi…
- CVE-2026-22679CRITICALCVSS 9.8EG 9.82026-04-07
Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by…
- CVE-2026-22727HIGHCVSS 7.5EG 7.52026-03-17
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications a…
- CVE-2026-22731HIGHCVSS 8.1EG 8.22026-03-19
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additio…
- CVE-2026-22788HIGHCVSS 8.2EG 8.22026-01-12
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote atta…
- CVE-2026-22812HIGHCVSS 8.8EG 8.82026-01-12
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user…
- CVE-2026-22898CRITICALCVSS 9.8EG 9.82026-03-20
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the followi…
- CVE-2026-22924CRITICALCVSS 9.1EG 9.12026-05-12
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attack…
- CVE-2026-2339HIGHCVSS 7.5EG 7.52026-03-10
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion, Privilege Abuse, Command Injection. This issue affects Liderahenk: before 3.5.1.
- CVE-2026-23662HIGHCVSS 7.5EG 7.52026-03-10
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- CVE-2026-23693CRITICALCVSS 10.0EG 10.02026-02-23
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authenticati…
- CVE-2026-23744CRITICALCVSS 9.8EG 9.82026-01-16
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the ins…
- CVE-2026-23746CRITICALCVSS 9.3EG 9.32026-01-15
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCa…
- CVE-2026-23751CRITICALCVSS 9.8EG 9.82026-04-23
Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and …
- CVE-2026-23767CRITICALCVSS 9.8EG 9.82026-03-05
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transm…
- CVE-2026-23944CRITICALCVSS 9.8EG 9.82026-01-19
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be proxied to remote environment agents, allowing access to remote environment resources without …
- CVE-2026-24062HIGHCVSS 7.8EG 7.82026-03-18
The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privil…
- CVE-2026-24068HIGHCVSS 8.8EG 8.82026-03-26
The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC framework to validate if a client should be allowed to connect to the XPC listener, does not v…
- CVE-2026-24088HIGHCVSS 8.2EG 8.22026-06-01
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
- CVE-2026-24090HIGHCVSS 7.1EG 7.12026-06-01
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
- CVE-2026-24124CRITICALCVSS 9.8EG 9.82026-01-22
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing c…
- CVE-2026-2417CRITICALCVSS 9.3EG 9.32026-03-24
A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privil…
- CVE-2026-24177HIGHCVSS 7.7EG 7.72026-04-21
NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure.
- CVE-2026-24229HIGHCVSS 7.3EG 7.32026-07-14
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of th…
- CVE-2026-24259MEDIUMCVSS 6.4EG 6.42026-07-14
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information d…
- CVE-2026-24423CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-23
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the ma…
- CVE-2026-24728CRITICALCVSS 9.3EG 9.32026-01-30
A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authent…
- CVE-2026-24731CRITICALCVSS 9.8EG 9.82026-02-27
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint …
- CVE-2026-24789CRITICALCVSS 9.8EG 9.82026-02-11
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
- CVE-2026-24790HIGHCVSS 8.2EG 8.22026-02-20
The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
- CVE-2026-2491MEDIUMCVSS 6.3EG 6.32026-03-16
Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Socomec DIRIS A-40 power monitoring devices. Authentication is not …
- CVE-2026-25058HIGHCVSS 7.5EG 7.52026-04-20
Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns t…
- CVE-2026-25071HIGHCVSS 7.5EG 7.52026-03-07
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. …
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →