VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 131 of 149
  • CVE-2026-49254lowJul 2, 2026
    risk 0.07cvss epss

    ### Summary The Dragonfly Manager exposes `GET /api/v1/oauth` and `GET /api/v1/oauth/:id` to unauthenticated clients. The response body deserializes the entire `manager/models.Oauth` struct, which includes the `client_secret` field. Any network-reachable attacker can read the…

  • CVE-2020-12492LowNov 25, 2024
    risk 0.07cvss epss 0.00

    Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.

  • CVE-2023-4506LowSep 27, 2023
    risk 0.07cvss 2.2epss 0.01

    The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with…

  • CVE-2021-27358HigMar 18, 2021
    risk 0.07cvss 7.5epss 0.83

    The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

  • CVE-2022-23944CriJan 25, 2022
    risk 0.06cvss 9.1epss 0.79

    User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

  • CVE-2018-18264HigJan 3, 2019
    risk 0.06cvss 7.5epss 0.70

    Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

  • CVE-2021-29442HigApr 27, 2021
    risk 0.05cvss 8.6epss 0.66

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove…

  • CVE-2009-1780May 22, 2009
    risk 0.03cvss epss 0.04

    admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

  • CVE-2024-6842HigMar 20, 2025
    risk 0.02cvss 7.5epss 0.31

    In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be…

  • CVE-2007-0956Apr 6, 2007
    risk 0.02cvss epss 0.30

    The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.

  • CVE-2026-25703HigAug 5, 2026
    risk 0.00cvss 7.3epss 0.00

    NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

  • CVE-2026-69703CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke…

  • CVE-2026-58071HigAug 4, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.

  • CVE-2026-61514CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the…

  • CVE-2026-67610HigAug 3, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks…

  • CVE-2026-41452CriAug 3, 2026
    risk 0.00cvss 9.8epss 0.01

    Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to…

  • CVE-2026-68578HigAug 2, 2026
    risk 0.00cvss 7.5epss 0.00

    ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary…

  • CVE-2026-65311MedJul 31, 2026
    risk 0.00cvss 5.3epss 0.00

    The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service…

  • CVE-2026-65310HigJul 31, 2026
    risk 0.00cvss 7.5epss 0.00

    ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values…

  • CVE-2026-67594CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing…