CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 42 of 67
- CVE-2026-15576MEDIUMCVSS 6.9EG 6.92026-08-21
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request U…
- CVE-2026-15581HIGHCVSS 8.0EG 8.02026-08-10
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or del…
- CVE-2026-15706CRITICALCVSS 9.8EG 9.82026-08-20
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Managem…
- CVE-2026-1579CRITICALCVSS 9.8EG 9.82026-03-31
The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sen…
- CVE-2026-15978HIGHCVSS 7.5EG 7.52026-07-30
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data tran…
- CVE-2026-16015MEDIUMCVSS 6.3EG 6.32026-07-17
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead …
- CVE-2026-1603CRITICALCVSS 7.5EG 9.0⚠ KEV2026-02-10
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
- CVE-2026-16209HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The att…
- CVE-2026-16210HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Rem…
- CVE-2026-16242CRITICALCVSS 9.4EG 9.42026-07-20
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not vali…
- CVE-2026-1632CRITICALCVSS 9.1EG 9.12026-02-03
MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset t…
- CVE-2026-1633CRITICALCVSS 10.0EG 10.02026-02-04
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.
- CVE-2026-16527HIGHCVSS 7.3EG 7.32026-07-30
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
- CVE-2026-16646MEDIUMCVSS 5.7EG 5.72026-08-25
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
- CVE-2026-1670CRITICALCVSS 9.8EG 9.82026-02-17
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
- CVE-2026-16771HIGHCVSS 8.8EG 8.82026-07-28
In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed …
- CVE-2026-16876CRITICALCVSS 9.3EG 9.32026-09-07
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
- CVE-2026-17057CRITICALCVSS 9.1EG 9.12026-09-04
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
- CVE-2026-1724HIGHCVSS 7.5EG 7.52026-03-25
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to i…
- CVE-2026-1729CRITICALCVSS 9.8EG 9.82026-02-12
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_use…
- CVE-2026-17348MEDIUMCVSS 6.5EG 6.52026-07-31
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped wi…
- CVE-2026-1775HIGHCVSS 8.8EG 8.82026-03-03
The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameters and run operational commands when specially crafted packets are sent to the device.
- CVE-2026-18111HIGHCVSS 8.5EG 8.52026-09-15
Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuffi…
- CVE-2026-18265CRITICALCVSS 9.8EG 9.82026-08-20
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit …
- CVE-2026-1840HIGHCVSS 7.5EG 7.52026-06-24
The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter o…
- CVE-2026-18673MEDIUMCVSS 5.3EG 5.32026-08-12
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach t…
- CVE-2026-18771HIGHCVSS 7.5EG 7.52026-09-01
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from…
- CVE-2026-18810HIGHCVSS 7.3EG 7.32026-08-04
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor w…
- CVE-2026-18941HIGHCVSS 7.7EG 7.72026-08-10
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to fe…
- CVE-2026-18990HIGHCVSS 7.3EG 7.32026-08-06
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from …
- CVE-2026-1900MEDIUMCVSS 6.5EG 6.52026-04-07
The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.
- CVE-2026-1919MEDIUMCVSS 5.3EG 5.32026-03-10
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and includi…
- CVE-2026-1920MEDIUMCVSS 5.3EG 5.32026-03-10
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'Extension_Controller::update_item_permissions_check…
- CVE-2026-19397HIGHCVSS 7.7EG 7.72026-09-08
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' …
- CVE-2026-19426HIGHCVSS 8.2EG 8.22026-08-12
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.
- CVE-2026-19441MEDIUMCVSS 5.3EG 5.32026-08-21
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. NOTE: The vendor was contacted and it was learned that the product is not…
- CVE-2026-19749LOWCVSS 3.7EG 3.72026-08-13
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulati…
- CVE-2026-19853MEDIUMCVSS 5.3EG 5.32026-08-24
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.
- CVE-2026-19875HIGHCVSS 7.5EG 7.52026-08-19
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
- CVE-2026-19908HIGHCVSS 7.1EG 7.12026-08-14
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentica…
- CVE-2026-19971MEDIUMCVSS 4.7EG 4.72026-08-17
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the lo…
- CVE-2026-20223CRITICALCVSS 10.0EG 10.02026-05-20
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is…
- CVE-2026-20253CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-10
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL s…
- CVE-2026-20326CRITICALCVSS 9.8EG 9.82026-09-16
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that a…
- CVE-2026-20343HIGHCVSS 7.5EG 7.52026-09-16
A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authenticat…
- CVE-2026-20357CRITICALCVSS 10.0EG 10.02026-08-19
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address…
- CVE-2026-2065HIGHCVSS 8.8EG 8.82026-02-06
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. …
- CVE-2026-20781CRITICALCVSS 9.8EG 9.82026-02-27
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint …
- CVE-2026-20803HIGHCVSS 7.2EG 7.22026-01-13
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20995MEDIUMCVSS 5.3EG 5.32026-03-16
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →