VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 132 of 149
  • CVE-2026-67208CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.04

    Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected…

  • CVE-2026-15978HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model…

  • CVE-2026-12722HigJul 30, 2026
    risk 0.00cvss 8.2epss 0.00

    Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.

  • CVE-2026-54367HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId…

  • CVE-2026-54365HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a…

  • CVE-2026-44101CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

  • CVE-2026-44100CriJul 30, 2026
    risk 0.00cvss 9.4epss 0.00

    The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

  • CVE-2026-44090CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

  • CVE-2026-47858HigJul 30, 2026
    risk 0.00cvss 8.0epss 0.00

    Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for…

  • CVE-2026-13306MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this…

  • CVE-2026-5057HigJul 29, 2026
    risk 0.00cvss 7.5epss 0.00

    ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The…

  • CVE-2026-14529CriJul 29, 2026
    risk 0.00cvss 9.4epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

  • CVE-2026-60113CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending…

  • CVE-2026-60112CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers…

  • CVE-2026-16771HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows…

  • CVE-2026-7187HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not…

  • CVE-2026-12989HigJul 27, 2026
    risk 0.00cvss epss 0.00

    A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of…

  • CVE-2026-66006MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to…

  • CVE-2026-56163CriJul 24, 2026
    risk 0.00cvss 10.0epss 0.01

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-63765HigJul 23, 2026
    risk 0.00cvss 8.2epss 0.00

    Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account…