VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 139 of 169
  • CVE-2026-11539MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

  • CVE-2026-71568MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.00

    In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

  • CVE-2026-76447MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing…

  • CVE-2026-76444MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository…

  • CVE-2026-76439MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to…

  • CVE-2026-89263MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user…

  • CVE-2026-79961MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,…

  • CVE-2026-85701MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing…

  • CVE-2026-85637MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has…

  • CVE-2026-85636MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is…

  • CVE-2025-15481MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.

  • CVE-2026-80234MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.01

    CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.

  • CVE-2026-19853MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.00

    NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.

  • CVE-2026-69228MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS…

  • CVE-2026-19441MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026.  NOTE: The vendor was contacted and it was learned that the product is not supported.

  • CVE-2026-75919MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.01

    phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and…

  • CVE-2026-71203MedAug 5, 2026
    risk 0.34cvss 5.3epss 0.00

    changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor…

  • CVE-2026-65311MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service…

  • CVE-2025-68640MedJul 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may…

  • CVE-2026-16015MedJul 17, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit…