VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,961)

page 143 of 149
  • CVE-2026-50759HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

  • CVE-2025-68640MedJul 21, 2026
    risk 0.00cvss 5.3epss 0.00

    The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may…

  • CVE-2026-57495HigJul 20, 2026
    risk 0.00cvss epss 0.00

    AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail…

  • CVE-2026-46555HigJul 20, 2026
    risk 0.00cvss 7.7epss 0.00

    WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the…

  • CVE-2026-63429HigJul 20, 2026
    risk 0.00cvss 8.6epss 0.00

    HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX,…

  • CVE-2026-63757HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauthenticated attackers can enumerate…

  • CVE-2026-16210HigJul 19, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Remote exploitation of the attack is…

  • CVE-2026-16209HigJul 19, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be launched remotely. The…

  • CVE-2026-8505CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False…

  • CVE-2026-9103CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN…

  • CVE-2026-9202CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE…

  • CVE-2026-63101HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV…

  • CVE-2026-12691HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-63098MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the…

  • CVE-2026-16015MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit…

  • CVE-2024-34268HigJul 16, 2026
    risk 0.00cvss 7.1epss 0.00

    EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.

  • CVE-2026-6511MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.

  • CVE-2026-63087CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.00

    Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the…

  • CVE-2026-57206HigJul 16, 2026
    risk 0.00cvss 8.6epss 0.01

    SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST…

  • CVE-2026-58658HigJul 15, 2026
    risk 0.00cvss 8.2epss 0.00

    GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker configuration by exploiting unprotected /serveLogs and /debug endpoints on…