VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,961)

page 13 of 149
  • CVE-2019-25568CriMar 21, 2026
    risk 0.64cvss 9.8epss 0.00

    Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable,…

  • CVE-2026-22898CriMar 20, 2026
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

  • CVE-2026-21992CriMar 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and …

  • CVE-2026-3207CriMar 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

  • CVE-2026-4312CriMar 17, 2026
    risk 0.64cvss 9.8epss 0.00

    GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.

  • CVE-2026-22192CriMar 13, 2026
    risk 0.64cvss 9.9epss 0.00

    Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass…

  • CVE-2026-23767CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.00

    ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or…

  • CVE-2026-27012CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly…

  • CVE-2026-22207CriFeb 26, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without…

  • CVE-2025-14577CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican…

  • CVE-2025-30410CriFeb 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect…

  • CVE-2025-8350CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The…

  • CVE-2026-1670CriFeb 17, 2026
    risk 0.64cvss 9.8epss 0.01

    The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

  • CVE-2026-26333CriFeb 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with…

  • CVE-2026-1729CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it…

  • CVE-2026-25084CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

  • CVE-2026-24789CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

  • CVE-2026-2249CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in…

  • CVE-2026-2248CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results…

  • CVE-2025-8025CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was…