VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,961)

page 144 of 149
  • CVE-2026-61613HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling…

  • CVE-2026-48325CriJul 14, 2026
    risk 0.00cvss 9.3epss 0.01

    ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-24259MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-24229HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to…

  • CVE-2026-48252HigJul 14, 2026
    risk 0.00cvss 8.6epss 0.00

    Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this…

  • CVE-2026-50451HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50444HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-57969HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50333HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49174MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

  • CVE-2026-58319CriJul 14, 2026
    risk 0.00cvss 9.1epss 0.01

    Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and…

  • CVE-2026-62327CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.00

    9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint.…

  • CVE-2026-59801CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.02

    9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under…

  • CVE-2026-6847CriJul 13, 2026
    risk 0.00cvss epss 0.01

    Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and…

  • CVE-2026-22096CriJul 13, 2026
    risk 0.00cvss epss 0.00

    The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.

  • CVE-2026-15491HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release…

  • CVE-2026-57476MedJul 10, 2026
    risk 0.00cvss 4.8epss 0.00

    Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network…

  • CVE-2026-57475MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted…

  • CVE-2026-56675HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify…

  • CVE-2026-40006HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on…