CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 59 of 67
- CVE-2026-61161CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerabi…
- CVE-2026-61163HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenti…
- CVE-2026-61167CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
- CVE-2026-61168HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to …
- CVE-2026-61170HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP …
- CVE-2026-61171CRITICALCVSS 9.1EG 9.12026-07-21
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
- CVE-2026-61175CRITICALCVSS 9.3EG 9.32026-07-21
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker wi…
- CVE-2026-61176MEDIUMCVSS 6.7EG 6.72026-07-21
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker wi…
- CVE-2026-61178CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated…
- CVE-2026-61179HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows l…
- CVE-2026-61180HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows l…
- CVE-2026-61183CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2026-61186CRITICALCVSS 9.4EG 9.42026-07-21
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with net…
- CVE-2026-61188HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privilege…
- CVE-2026-61196CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated atta…
- CVE-2026-61201CRITICALCVSS 9.0EG 9.02026-07-21
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker …
- CVE-2026-61203CRITICALCVSS 9.4EG 9.42026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network acce…
- CVE-2026-61225HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated a…
- CVE-2026-61233CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker w…
- CVE-2026-61239CRITICALCVSS 9.9EG 9.92026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-61243HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2026-61245CRITICALCVSS 9.8EG 9.82026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker wi…
- CVE-2026-61246HIGHCVSS 8.8EG 8.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-61247MEDIUMCVSS 4.8EG 4.82026-07-21
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker…
- CVE-2026-6126HIGHCVSS 7.3EG 7.32026-04-12
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to init…
- CVE-2026-61267HIGHCVSS 7.3EG 7.32026-07-21
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated …
- CVE-2026-61285HIGHCVSS 7.2EG 7.22026-07-21
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows high privileg…
- CVE-2026-6129HIGHCVSS 7.3EG 7.32026-04-12
A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated…
- CVE-2026-61307HIGHCVSS 8.1EG 8.12026-08-18
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unaut…
- CVE-2026-61311HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with net…
- CVE-2026-61320HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with networ…
- CVE-2026-61322HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acce…
- CVE-2026-61344MEDIUMCVSS 5.3EG 5.32026-07-09
The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.
- CVE-2026-61356HIGHCVSS 7.8EG 7.82026-08-11
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-61364HIGHCVSS 7.8EG 7.82026-08-11
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-61365HIGHCVSS 7.8EG 7.82026-08-11
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-61367HIGHCVSS 7.8EG 7.82026-08-11
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-61514CRITICALCVSS 9.8EG 9.82026-08-04
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credenti…
- CVE-2026-61590HIGHCVSS 7.4EG 7.42026-09-16
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`…
- CVE-2026-61594CRITICALCVSS 9.1EG 9.12026-09-16
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` …
- CVE-2026-61613HIGHCVSS 7.7EG 7.72026-07-15
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthe…
- CVE-2026-61808CRITICALCVSS 9.8EG 9.82026-08-07
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read …
- CVE-2026-61884CRITICALCVSS 9.8EG 9.82026-07-24
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface w…
- CVE-2026-61891HIGHCVSS 7.5EG 7.52026-08-05
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and str…
- CVE-2026-62241CRITICALCVSS 9.1EG 9.12026-07-17
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing user…
- CVE-2026-62325CRITICALCVSS 9.1EG 9.12026-07-28
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -…
- CVE-2026-62327CRITICALCVSS 9.1EG 9.12026-07-13
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request …
- CVE-2026-62422CRITICALCVSS 9.8EG 10.02026-07-14
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
- CVE-2026-62447HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …
- CVE-2026-62464HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →