VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 104 of 150
  • CVE-2026-27595HigFeb 25, 2026
    risk 0.42cvss 7.5epss 0.00

    Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, allow unauthenticated remote attackers to…

  • CVE-2026-27584HigFeb 24, 2026
    risk 0.42cvss 7.5epss 0.00

    Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensitive bank account balance and…

  • CVE-2026-26319HigFeb 19, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthenticated callers to forge Telnyx events.…

  • CVE-2026-25791HigFeb 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because…

  • CVE-2026-25751HigFeb 6, 2026
    risk 0.42cvss 7.5epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker…

  • CVE-2022-50980MedFeb 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.

  • CVE-2022-50979MedFeb 2, 2026
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

  • CVE-2026-1410MedJan 26, 2026
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipulation results in missing authentication. An attack on the physical device is feasible. This attack is characterized by high…

  • CVE-2025-65828MedDec 10, 2025
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear config. Clear config would disassociate the…

  • CVE-2025-12969MedNov 24, 2025
    risk 0.42cvss 6.5epss 0.01

    Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data.…

  • CVE-2025-64307MedNov 15, 2025
    risk 0.42cvss 6.5epss 0.00

    The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and…

  • CVE-2025-40817MedNov 11, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2)…

  • CVE-2025-10746MedOct 4, 2025
    risk 0.42cvss 6.5epss 0.00

    The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to missing capability checks and nonce verification on functions hooked to 'init'. This makes it possible for unauthenticated…

  • CVE-2025-59358HigSep 15, 2025
    risk 0.42cvss 7.5epss 0.01

    The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.

  • CVE-2025-7045MedSep 6, 2025
    risk 0.42cvss 6.5epss 0.00

    The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible for unauthenticated…

  • CVE-2025-52894HigJun 25, 2025
    risk 0.42cvss 7.5epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 allowed an attacker to perform unauthenticated, unaudited cancellation of root rekey and recovery rekey operations,…

  • CVE-2025-27803MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or…

  • CVE-2025-4560MedMay 12, 2025
    risk 0.42cvss 6.5epss 0.00

    The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, viewing and editing IP settings, and uploading files.

  • CVE-2025-32377MedApr 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is…

  • CVE-2025-3474MedApr 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.