VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 117 of 169
  • CVE-2024-22449MedFeb 1, 2024
    risk 0.43cvss 6.6epss 0.00

    Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.

  • CVE-2021-46006MedMar 30, 2022
    risk 0.43cvss 6.5epss 0.06

    In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.

  • CVE-2022-20060MedMar 10, 2022
    risk 0.43cvss 6.6epss 0.00

    In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is…

  • CVE-2020-13405HigJul 16, 2020
    risk 0.43cvss 7.5epss 0.14

    userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

  • CVE-2020-9473MedApr 6, 2020
    risk 0.43cvss 6.6epss 0.01

    The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, an attacker with access to the network can get root access on the gateway.

  • CVE-2019-19143MedJan 27, 2020
    risk 0.43cvss 6.1epss 0.07

    TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.

  • CVE-2026-102811HigSep 29, 2026
    risk 0.42cvss 7.5epss 0.01

    Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit…

  • CVE-2026-57443HigSep 25, 2026
    risk 0.42cvss 7.5epss 0.01

    SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any…

  • CVE-2026-100192MedSep 25, 2026
    risk 0.42cvss 6.5epss 0.00

    X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's…

  • CVE-2026-89034MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed…

  • CVE-2026-88065HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.01

    `tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and…

  • CVE-2026-68953MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.01

    The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

  • CVE-2026-89027MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any…

  • CVE-2026-82784MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.

  • CVE-2026-90513MedSep 13, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument…

  • CVE-2026-89261MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.01

    MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete…

  • CVE-2026-89250HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.01

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed…

  • CVE-2026-9336MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.

  • CVE-2026-49363HigSep 10, 2026
    risk 0.42cvss 7.5epss 0.01

    An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through…

  • CVE-2026-87924MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.01

    A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument…