CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,961)
page 144 of 149| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-61613 | Hig | 0.00 | — | 0.00 | Jul 15, 2026 | Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling… | ||
| CVE-2026-48325 | Cri | 0.00 | 9.3 | 0.01 | Jul 14, 2026 | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | ||
| CVE-2026-24259 | Med | 0.00 | 6.4 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | ||
| CVE-2026-24229 | Hig | 0.00 | 7.3 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to… | ||
| CVE-2026-48252 | Hig | 0.00 | 8.6 | 0.00 | Jul 14, 2026 | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this… | ||
| CVE-2026-50451 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50444 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-57969 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-50333 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49174 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-58319 | Cri | 0.00 | 9.1 | 0.01 | Jul 14, 2026 | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and… | ||
| CVE-2026-62327 | Cri | 0.00 | 9.1 | 0.00 | Jul 13, 2026 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint.… | ||
| CVE-2026-59801 | Cri | 0.00 | 9.8 | 0.02 | Jul 13, 2026 | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under… | ||
| CVE-2026-6847 | Cri | 0.00 | — | 0.01 | Jul 13, 2026 | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and… | ||
| CVE-2026-22096 | — | Cri | 0.00 | — | 0.00 | Jul 13, 2026 | The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints. | |
| CVE-2026-15491 | Hig | 0.00 | 7.3 | 0.00 | Jul 12, 2026 | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release… | ||
| CVE-2026-57476 | Med | 0.00 | 4.8 | 0.00 | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network… | ||
| CVE-2026-57475 | Med | 0.00 | 5.3 | 0.00 | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted… | ||
| CVE-2026-56675 | Hig | 0.00 | 8.3 | 0.00 | Jul 10, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify… | ||
| CVE-2026-40006 | Hig | 0.00 | 7.5 | 0.00 | Jul 10, 2026 | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on… |
- risk 0.00cvss —epss 0.00
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling…
- risk 0.00cvss 9.3epss 0.01
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- risk 0.00cvss 6.4epss 0.00
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- risk 0.00cvss 7.3epss 0.00
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to…
- risk 0.00cvss 8.6epss 0.00
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this…
- risk 0.00cvss 7.1epss 0.00
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.01
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 8.8epss 0.01
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 7.8epss 0.00
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.1epss 0.00
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- risk 0.00cvss 9.1epss 0.01
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and…
- risk 0.00cvss 9.1epss 0.00
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint.…
- risk 0.00cvss 9.8epss 0.02
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under…
- risk 0.00cvss —epss 0.01
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and…
- risk 0.00cvss —epss 0.00
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.
- risk 0.00cvss 7.3epss 0.00
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release…
- risk 0.00cvss 4.8epss 0.00
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network…
- risk 0.00cvss 5.3epss 0.00
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted…
- risk 0.00cvss 8.3epss 0.00
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify…
- risk 0.00cvss 7.5epss 0.00
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on…