VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 119 of 149
  • CVE-2018-1757MedSep 7, 2018
    risk 0.35cvss 5.3epss 0.02

    IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601.

  • CVE-2026-71203MedAug 5, 2026
    risk 0.34cvss 5.3epss 0.00

    changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor…

  • CVE-2026-31983MedJul 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the…

  • CVE-2026-56321MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and DELETE role_bindings routes, so unauthenticated requests reach the handler instead of being…

  • CVE-2026-8694MedJun 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.

  • CVE-2026-11848MedJun 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain partial system configuration information.

  • CVE-2026-10283MedJun 1, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. It is recommended to apply a patch to…

  • CVE-2026-8737MedMay 17, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a…

  • CVE-2026-45248MedMay 14, 2026
    risk 0.34cvss 5.3epss 0.00

    Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can access the endpoint without providing authentication…

  • CVE-2026-31245MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can…

  • CVE-2026-8031MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records of the component API Endpoint. The manipulation results in missing authentication. The attack can be…

  • CVE-2026-32962MedApr 20, 2026
    risk 0.34cvss 5.3epss 0.00

    SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.

  • CVE-2026-32957MedApr 20, 2026
    risk 0.34cvss 5.3epss 0.00

    SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication.

  • CVE-2026-35450MedApr 6, 2026
    risk 0.34cvss 5.3epss 0.00

    WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints…

  • CVE-2026-28767MedApr 3, 2026
    risk 0.34cvss 5.3epss 0.00

    A specific administrative endpoint notifications is accessible without proper authentication.

  • CVE-2026-33366MedMar 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.

  • CVE-2026-4187MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateLocalDevInfo.jsp of the component Device Identifier Handler. Such manipulation of the argument username/password leads to missing…

  • CVE-2026-20995MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.

  • CVE-2025-14294MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback…

  • CVE-2025-6792MedFeb 14, 2026
    risk 0.34cvss 5.3epss 0.00

    The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for…