CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
2,826 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 44 of 57
- CVE-2026-27843CRITICALCVSS 9.1EG 9.12026-04-24
A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or disruptive values to…
- CVE-2026-27846MEDIUMCVSS 6.2EG 6.22026-02-25
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network to gain access to sensitive information, including the password for admin access to th…
- CVE-2026-27897HIGHCVSS 7.1EG 7.12026-03-11
Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename a…
- CVE-2026-27944CRITICALCVSS 9.8EG 9.82026-03-05
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security resp…
- CVE-2026-28229HIGHCVSS 7.5EG 7.52026-03-11
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTem…
- CVE-2026-28352MEDIUMCVSS 6.5EG 6.52026-02-27
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check, allowing unauthenticated…
- CVE-2026-2844HIGHCVSS 7.5EG 7.52026-02-28
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.
- CVE-2026-28450HIGHCVSS 8.2EG 8.22026-03-05
OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/channels/nostr/:accountId/profile/import that allow reading and modifying …
- CVE-2026-28458MEDIUMCVSS 5.4EG 5.42026-03-05
OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect v…
- CVE-2026-28468HIGHCVSS 7.7EG 7.72026-03-05
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests without requiring gateway authentication, allowing local attackers to access browser control en…
- CVE-2026-28472CRITICALCVSS 9.8EG 9.82026-03-05
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway wi…
- CVE-2026-28485HIGHCVSS 7.8EG 7.82026-03-05
OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network…
- CVE-2026-28766CRITICALCVSS 7.5EG 9.32026-04-03
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
- CVE-2026-28767MEDIUMCVSS 5.3EG 5.32026-04-03
A specific administrative endpoint notifications is accessible without proper authentication.
- CVE-2026-29132HIGHCVSS 7.5EG 7.52026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.
- CVE-2026-29606MEDIUMCVSS 6.5EG 6.52026-03-05
OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests when the tunnel.allowNgrokFreeTierLoopbackBypass option is explicitly enabled. An externa…
- CVE-2026-29613MEDIUMCVSS 5.9EG 5.92026-03-05
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing byp…
- CVE-2026-29796CRITICALCVSS 9.8EG 9.42026-03-20
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint usi…
- CVE-2026-3053HIGHCVSS 9.8EG 7.32026-02-24
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation …
- CVE-2026-30799HIGHCVSS 8.1EG 8.12026-06-17
Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.*, from 6.1.0 before…
- CVE-2026-30824HIGHCVSS 9.8EG 7.72026-03-07
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated…
- CVE-2026-30846HIGHCVSS 7.5EG 7.52026-03-06
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authenticati…
- CVE-2026-30885MEDIUMCVSS 5.3EG 5.32026-03-10
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate u…
- CVE-2026-30933HIGHCVSS 7.5EG 7.52026-03-10
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/shar…
- CVE-2026-31071CRITICALCVSS 9.1EG 9.12026-05-19
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserDat…
- CVE-2026-31240HIGHCVSS 7.5EG 7.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are exposed without any verification of the reque…
- CVE-2026-31241MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g…
- CVE-2026-31242CRITICALCVSS 9.1EG 9.12026-05-12
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, …
- CVE-2026-31243MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that trigger…
- CVE-2026-31244MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrary memory records without verifying their…
- CVE-2026-31245MEDIUMCVSS 5.3EG 5.32026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or p…
- CVE-2026-31846MEDIUMCVSS 6.5EG 6.52026-03-23
Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator passwo…
- CVE-2026-31881CRITICALCVSS 9.8EG 9.82026-03-11
Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, resulting in full account takeover. The endpoint POST /api/auth/res…
- CVE-2026-31882HIGHCVSS 7.5EG 7.52026-03-13
Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all Server-Sent Events (SSE) endpoints are accessible without any credentials. Thi…
- CVE-2026-3192MEDIUMCVSS 8.1EG 5.62026-02-25
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. T…
- CVE-2026-3194MEDIUMCVSS 7.0EG 4.52026-02-25
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can on…
- CVE-2026-31944HIGHCVSS 7.6EG 7.62026-03-13
LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the…
- CVE-2026-31983MEDIUMCVSS 5.3EG 5.32026-07-09
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their p…
- CVE-2026-32041MEDIUMCVSS 6.9EG 6.92026-03-19
OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can e…
- CVE-2026-32064HIGHCVSS 7.7EG 7.72026-03-21
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can c…
- CVE-2026-3207CRITICALCVSS 9.8EG 9.82026-03-17
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
- CVE-2026-32211CRITICALCVSS 7.5EG 9.12026-04-03
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
- CVE-2026-32231HIGHCVSS 8.2EG 8.22026-03-12
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to those untrusted values. Because authentica…
- CVE-2026-32291MEDIUMCVSS 6.8EG 6.82026-03-17
The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.
- CVE-2026-32296HIGHCVSS 8.2EG 8.22026-03-17
Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to change the saved configured Wi-Fi network to one of the attacker's choosing, or …
- CVE-2026-32297HIGHCVSS 7.5EG 7.52026-03-17
The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system binaries could allow an attacker to take complete control of a …
- CVE-2026-32326MEDIUMCVSS 5.7EG 5.72026-03-25
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.
- CVE-2026-32594HIGHCVSS 7.3EG 7.32026-03-16
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middlew…
- CVE-2026-32646HIGHCVSS 7.5EG 7.52026-04-03
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
- CVE-2026-32896MEDIUMCVSS 4.8EG 4.82026-03-21
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →