CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 51 of 67
- CVE-2026-4810CRITICALCVSS 9.3EG 9.32026-04-13
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to exec…
- CVE-2026-48106HIGHCVSS 8.3EG 8.32026-08-21
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode) o…
- CVE-2026-48252HIGHCVSS 8.6EG 8.62026-07-14
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unautho…
- CVE-2026-48325CRITICALCVSS 9.3EG 9.32026-07-14
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is…
- CVE-2026-48692HIGHCVSS 8.1EG 8.12026-05-26
FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment e…
- CVE-2026-48814CRITICALCVSS 9.1EG 9.12026-06-17
Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CV…
- CVE-2026-48911HIGHCVSS 7.5EG 7.52026-08-05
Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to ta…
- CVE-2026-48989HIGHCVSS 8.9EG 8.92026-06-17
Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=…
- CVE-2026-49174MEDIUMCVSS 6.1EG 6.12026-07-14
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- CVE-2026-49195HIGHCVSS 8.8EG 8.82026-05-29
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.
- CVE-2026-49217HIGHCVSS 7.5EG 7.52026-08-20
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field…
- CVE-2026-49254LOWCVSS 2.9EG 2.92026-07-02
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/han…
- CVE-2026-49257CRITICALCVSS 10.0EG 10.02026-06-18
mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP …
- CVE-2026-49357HIGHCVSS 8.8EG 8.82026-06-19
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable H…
- CVE-2026-49362HIGHCVSS 7.5EG 7.52026-09-10
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0…
- CVE-2026-49363HIGHCVSS 7.5EG 7.52026-09-10
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apach…
- CVE-2026-49364CRITICALCVSS 9.1EG 9.12026-09-10
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Activ…
- CVE-2026-49471HIGHCVSS 8.3EG 8.32026-07-07
Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port, with no authenticati…
- CVE-2026-4959HIGHCVSS 7.5EG 7.52026-03-27
A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument int…
- CVE-2026-49819CRITICALCVSS 9.8EG 9.82026-08-12
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuse…
- CVE-2026-49827CRITICALCVSS 9.8EG 9.82026-08-13
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Co…
- CVE-2026-49973CRITICALCVSS 9.4EG 9.42026-06-11
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any …
- CVE-2026-49980CRITICALCVSS 9.8EG 9.82026-06-16
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path…
- CVE-2026-5000HIGHCVSS 7.3EG 7.32026-03-28
A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of the file backend/server.py of the component API Endpoint. The manipulation of the argument B…
- CVE-2026-50025MEDIUMCVSS 6.9EG 6.92026-09-11
Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN provena…
- CVE-2026-50027CRITICALCVSS 9.8EG 9.82026-07-02
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an …
- CVE-2026-50082MEDIUMCVSS 5.3EG 6.52026-06-12
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.…
- CVE-2026-50085CRITICALCVSS 9.8EG 9.82026-06-12
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" an…
- CVE-2026-50136MEDIUMCVSS 5.3EG 5.32026-06-22
Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected…
- CVE-2026-50225CRITICALCVSS 9.1EG 9.12026-06-04
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
- CVE-2026-50242CRITICALCVSS 9.8EG 10.02026-06-19
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
- CVE-2026-50245HIGHCVSS 7.7EG 7.72026-06-11
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
- CVE-2026-50287HIGHCVSS 8.7EG 8.72026-06-01
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests with…
- CVE-2026-5029HIGHCVSS 8.7EG 8.72026-05-12
A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unauthenticated remote attacker can invoke …
- CVE-2026-50333HIGHCVSS 7.8EG 7.82026-07-14
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-50444HIGHCVSS 8.8EG 8.82026-07-14
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50451HIGHCVSS 7.8EG 7.82026-07-14
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-50507MEDIUMCVSS 6.8EG 6.82026-06-09
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2026-50512HIGHCVSS 7.8EG 7.82026-06-09
Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-50516CRITICALCVSS 9.4EG 9.42026-08-11
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-5057HIGHCVSS 7.5EG 7.52026-07-29
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to …
- CVE-2026-50604MEDIUMCVSS 4.9EG 4.92026-09-17
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain …
- CVE-2026-50608LOWCVSS 1.2EG 1.22026-09-17
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Un…
- CVE-2026-50759HIGHCVSS 7.5EG 7.52026-07-21
An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.
- CVE-2026-51937HIGHCVSS 7.5EG 7.52026-07-07
An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component
- CVE-2026-52480MEDIUMCVSS 6.5EG 6.52026-08-18
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service
- CVE-2026-5300CRITICALCVSS 9.1EG 9.12026-04-08
Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests
- CVE-2026-5320HIGHCVSS 7.3EG 7.32026-04-02
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component Chat API Endpoint. Performing a manipulation results in missing authenticati…
- CVE-2026-53469CRITICALCVSS 8.1EG 9.12026-06-10
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all cu…
- CVE-2026-53512CRITICALCVSS 9.1EG 9.12026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshTo…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →