CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 66 of 67
- CVE-2026-86292HIGHCVSS 7.3EG 7.32026-09-07
A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missin…
- CVE-2026-86293MEDIUMCVSS 6.5EG 6.52026-09-07
A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument …
- CVE-2026-86464CRITICALCVSS 9.9EG 9.92026-09-08
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …
- CVE-2026-86480CRITICALCVSS 9.8EG 9.82026-09-07
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
- CVE-2026-86486LOWCVSS 3.7EG 3.72026-09-07
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
- CVE-2026-86502HIGHCVSS 8.4EG 8.42026-09-07
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
- CVE-2026-86506MEDIUMCVSS 5.9EG 5.92026-09-07
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
- CVE-2026-86543CRITICALCVSS 9.8EG 9.82026-09-07
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to pr…
- CVE-2026-86727HIGHCVSS 7.5EG 7.52026-09-08
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can …
- CVE-2026-86728HIGHCVSS 7.5EG 7.52026-09-08
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user …
- CVE-2026-86801HIGHCVSS 8.8EG 8.82026-09-17
The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploade…
- CVE-2026-86808HIGHCVSS 7.3EG 7.32026-09-08
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. Th…
- CVE-2026-8694MEDIUMCVSS 5.3EG 5.32026-06-12
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
- CVE-2026-8697HIGHCVSS 8.8EG 8.82026-05-28
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to …
- CVE-2026-8706MEDIUMCVSS 6.5EG 6.52026-05-19
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability wa…
- CVE-2026-87128CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticat…
- CVE-2026-87129CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticat…
- CVE-2026-87170CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87173CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87175CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87176CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87184CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87188CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87195HIGHCVSS 7.4EG 7.42026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with …
- CVE-2026-87217CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-87223CRITICALCVSS 9.1EG 9.12026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-8732CRITICALCVSS 9.8EG 9.82026-05-29
The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_…
- CVE-2026-8737MEDIUMCVSS 5.3EG 5.32026-05-17
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Add…
- CVE-2026-87922HIGHCVSS 7.3EG 7.32026-09-09
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the comp…
- CVE-2026-87924MEDIUMCVSS 6.5EG 6.52026-09-09
A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such…
- CVE-2026-88018CRITICALCVSS 9.8EG 9.82026-09-10
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any cl…
- CVE-2026-88062CRITICALCVSS 9.5EG 9.52026-09-10
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand val…
- CVE-2026-88065HIGHCVSS 7.5EG 7.52026-09-15
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/phot…
- CVE-2026-88259HIGHCVSS 7.5EG 7.52026-09-18
CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
- CVE-2026-88263HIGHCVSS 7.5EG 7.52026-09-16
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to …
- CVE-2026-88285CRITICALCVSS 9.4EG 9.42026-09-10
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
- CVE-2026-89027MEDIUMCVSS 6.5EG 6.52026-09-15
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying…
- CVE-2026-89034MEDIUMCVSS 6.5EG 6.52026-09-16
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or …
- CVE-2026-89176HIGHCVSS 8.8EG 8.82026-09-11
WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a studen…
- CVE-2026-89250HIGHCVSS 7.5EG 7.52026-09-11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request…
- CVE-2026-89261MEDIUMCVSS 6.5EG 6.52026-09-11
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to …
- CVE-2026-89263MEDIUMCVSS 5.3EG 5.32026-09-11
MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotific…
- CVE-2026-9033MEDIUMCVSS 4.3EG 4.32026-08-20
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users mu…
- CVE-2026-90449MEDIUMCVSS 6.9EG 6.92026-09-11
When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All…
- CVE-2026-9045HIGHCVSS 7.8EG 7.82026-06-10
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privi…
- CVE-2026-90504HIGHCVSS 7.3EG 7.32026-09-13
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The att…
- CVE-2026-9051CRITICALCVSS 9.1EG 9.12026-05-29
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclo…
- CVE-2026-90513MEDIUMCVSS 6.5EG 6.52026-09-13
A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of…
- CVE-2026-90524HIGHCVSS 7.3EG 7.32026-09-13
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results…
- CVE-2026-90543MEDIUMCVSS 5.3EG 5.32026-09-12
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` …
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →