CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 60 of 67
- CVE-2026-62474MEDIUMCVSS 6.3EG 6.32026-07-21
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-62476HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacke…
- CVE-2026-62478HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-62493HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with n…
- CVE-2026-62496HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-62498HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2026-62534HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2026-62547HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker…
- CVE-2026-62645CRITICALCVSS 9.8EG 9.82026-09-08
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the…
- CVE-2026-6272HIGHCVSS 8.5EG 8.52026-04-24
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect t…
- CVE-2026-6274CRITICALCVSS 9.8EG 9.82026-06-05
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This i…
- CVE-2026-62777HIGHCVSS 7.8EG 7.82026-08-11
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-63087CRITICALCVSS 9.8EG 9.82026-07-16
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_…
- CVE-2026-63098MEDIUMCVSS 5.3EG 5.32026-07-17
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authen…
- CVE-2026-63101HIGHCVSS 7.5EG 7.52026-07-17
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submittin…
- CVE-2026-63429HIGHCVSS 8.6EG 8.62026-07-20
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous intern…
- CVE-2026-63455CRITICALCVSS 9.8EG 9.82026-08-04
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allo…
- CVE-2026-6348HIGHCVSS 8.8EG 8.82026-04-16
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the env…
- CVE-2026-63508CRITICALCVSS 10.0EG 10.02026-08-06
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-63647CRITICALCVSS 9.3EG 9.32026-09-18
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilt…
- CVE-2026-6369MEDIUMCVSS 5.5EG 5.52026-04-20
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the …
- CVE-2026-63722CRITICALCVSS 9.8EG 9.82026-08-19
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execu…
- CVE-2026-63757HIGHCVSS 8.8EG 8.82026-07-20
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauth…
- CVE-2026-6376HIGHCVSS 8.7EG 8.72026-04-23
A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive persona…
- CVE-2026-63765HIGHCVSS 8.2EG 8.22026-07-23
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing auth…
- CVE-2026-64812CRITICALCVSS 10.0EG 10.02026-07-23
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- CVE-2026-64921HIGHCVSS 8.8EG 8.82026-08-11
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-65012MEDIUMCVSS 5.3EG 5.32026-07-22
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerat…
- CVE-2026-65014MEDIUMCVSS 5.3EG 5.32026-07-22
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to …
- CVE-2026-65105HIGHCVSS 8.1EG 8.12026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosur…
- CVE-2026-6511MEDIUMCVSS 5.5EG 5.52026-07-16
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same …
- CVE-2026-65310HIGHCVSS 7.5EG 7.52026-07-31
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with netw…
- CVE-2026-65311MEDIUMCVSS 5.3EG 5.32026-07-31
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attac…
- CVE-2026-65319HIGHCVSS 7.5EG 7.52026-07-21
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the autho…
- CVE-2026-6577HIGHCVSS 7.3EG 7.32026-04-19
A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The …
- CVE-2026-6579MEDIUMCVSS 6.5EG 6.52026-04-19
A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiat…
- CVE-2026-6582HIGHCVSS 7.3EG 7.32026-04-19
A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the component Vector Database Management Endpoint. Executing …
- CVE-2026-6588MEDIUMCVSS 6.5EG 6.52026-04-20
A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can l…
- CVE-2026-65941HIGHCVSS 8.8EG 8.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
- CVE-2026-65956CRITICALCVSS 10.0EG 10.02026-08-26
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and S…
- CVE-2026-66006MEDIUMCVSS 5.3EG 5.32026-07-24
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after…
- CVE-2026-66047HIGHCVSS 8.1EG 8.12026-08-31
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit con…
- CVE-2026-66098MEDIUMCVSS 6.5EG 6.52026-08-11
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracki…
- CVE-2026-66139MEDIUMCVSS 4.8EG 4.82026-07-24
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
- CVE-2026-6673MEDIUMCVSS 6.4EG 6.42026-06-22
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret and disrupt…
- CVE-2026-66875HIGHCVSS 8.8EG 8.82026-08-11
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormon…
- CVE-2026-67208CRITICALCVSS 9.8EG 9.82026-07-30
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attac…
- CVE-2026-67277CRITICALCVSS 8.2EG 9.0⚠ KEV2026-09-05
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an …
- CVE-2026-67349HIGHCVSS 7.5EG 7.52026-07-30
OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is un…
- CVE-2026-6736MEDIUMCVSS 6.5EG 6.52026-05-07
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When external authentication wa…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →