CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 61 of 67
- CVE-2026-67426CRITICALCVSS 9.3EG 9.32026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supp…
- CVE-2026-67578HIGHCVSS 7.5EG 7.52026-08-25
FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.
- CVE-2026-67593CRITICALCVSS 9.1EG 9.12026-09-10
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Ap…
- CVE-2026-67594CRITICALCVSS 9.8EG 9.82026-07-30
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied t…
- CVE-2026-67610HIGHCVSS 8.1EG 8.12026-08-03
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a se…
- CVE-2026-67966CRITICALCVSS 9.8EG 9.82026-08-17
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
- CVE-2026-68070HIGHCVSS 8.8EG 8.82026-09-15
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
- CVE-2026-6847CRITICALCVSS 9.3EG 9.32026-07-13
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by prov…
- CVE-2026-68502CRITICALCVSS 9.8EG 9.82026-07-30
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd…
- CVE-2026-68578HIGHCVSS 7.5EG 7.52026-08-02
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, sch…
- CVE-2026-68929CRITICALCVSS 9.3EG 9.32026-08-27
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identi…
- CVE-2026-68953MEDIUMCVSS 6.5EG 6.52026-09-15
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
- CVE-2026-69091HIGHCVSS 7.5EG 7.52026-08-03
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unau…
- CVE-2026-69111HIGHCVSS 7.5EG 7.52026-08-05
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers…
- CVE-2026-69228MEDIUMCVSS 5.3EG 5.32026-08-21
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenti…
- CVE-2026-69321MEDIUMCVSS 5.5EG 5.52026-09-08
Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.
- CVE-2026-69415MEDIUMCVSS 6.8EG 6.82026-09-08
Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69528HIGHCVSS 7.8EG 7.82026-09-08
Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-69554MEDIUMCVSS 5.5EG 5.52026-09-08
Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
- CVE-2026-69674MEDIUMCVSS 5.5EG 5.52026-09-08
Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.
- CVE-2026-69703CRITICALCVSS 9.8EG 9.82026-08-04
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ign…
- CVE-2026-70352CRITICALCVSS 10.0EG 10.02026-09-03
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-7042HIGHCVSS 7.3EG 7.32026-04-26
A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST API Endpoint. Executing a manipulation can lead to missing authentication. It is possible …
- CVE-2026-70552CRITICALCVSS 9.8EG 9.82026-08-04
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-enc…
- CVE-2026-70559HIGHCVSS 7.5EG 7.52026-08-06
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session …
- CVE-2026-70693MEDIUMCVSS 6.3EG 6.32026-08-18
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows hig…
- CVE-2026-70711LOWCVSS 3.6EG 3.62026-08-18
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with l…
- CVE-2026-70748CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauth…
- CVE-2026-70756CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauth…
- CVE-2026-70757CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauth…
- CVE-2026-70805HIGHCVSS 8.1EG 8.12026-08-18
Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at…
- CVE-2026-70806HIGHCVSS 7.1EG 7.12026-08-18
Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with …
- CVE-2026-70861HIGHCVSS 7.2EG 7.22026-08-18
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacke…
- CVE-2026-70913CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with…
- CVE-2026-70918HIGHCVSS 8.8EG 8.82026-08-18
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network a…
- CVE-2026-70924HIGHCVSS 8.1EG 8.12026-08-18
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauth…
- CVE-2026-70926CRITICALCVSS 9.8EG 9.82026-08-18
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker w…
- CVE-2026-70930HIGHCVSS 7.5EG 7.52026-08-18
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attac…
- CVE-2026-70940HIGHCVSS 8.8EG 8.82026-08-18
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with net…
- CVE-2026-70953CRITICALCVSS 9.8EG 9.82026-08-18
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with n…
- CVE-2026-70954CRITICALCVSS 9.8EG 9.82026-08-18
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with n…
- CVE-2026-70956HIGHCVSS 8.8EG 8.82026-08-18
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low p…
- CVE-2026-70973HIGHCVSS 7.5EG 7.52026-08-18
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low…
- CVE-2026-70977CRITICALCVSS 9.1EG 9.12026-08-18
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerabilit…
- CVE-2026-70979CRITICALCVSS 9.1EG 9.12026-08-18
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerabilit…
- CVE-2026-71015CRITICALCVSS 9.1EG 9.12026-08-18
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerabi…
- CVE-2026-71067HIGHCVSS 8.8EG 8.82026-08-18
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network acce…
- CVE-2026-71068HIGHCVSS 8.1EG 8.12026-08-18
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network a…
- CVE-2026-7113MEDIUMCVSS 5.6EG 5.62026-04-27
A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_A…
- CVE-2026-71133CRITICALCVSS 10.0EG 10.02026-09-15
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticate…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →