VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 151 of 169
  • CVE-2026-93960MedSep 20, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to missing authentication. The attack may be…

  • CVE-2026-57128MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info requests. A network client that can reach the…

  • CVE-2026-75601MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated…

  • CVE-2026-76137LowAug 21, 2026
    risk 0.21cvss 3.3epss 0.00

    Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe.

  • CVE-2025-15567LowFeb 27, 2026
    risk 0.21cvss 3.3epss 0.00

    Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.

  • CVE-2025-14058LowJan 14, 2026
    risk 0.21cvss 3.2epss 0.00

    A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

  • CVE-2025-47870MedAug 21, 2025
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.

  • CVE-2024-6582MedSep 13, 2024
    risk 0.21cvss 4.3epss 0.00

    A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to…

  • CVE-2023-0463LowJan 26, 2023
    risk 0.21cvss 3.3epss 0.00

    The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.

  • CVE-2022-4018MedNov 16, 2022
    risk 0.21cvss 4.3epss 0.01

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

  • CVE-2026-84400LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing…

  • CVE-2026-47122MedJul 21, 2026
    risk 0.20cvss 4.2epss 0.00

    Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new…

  • CVE-2024-54153LowDec 4, 2024
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

  • CVE-2024-53701LowNov 29, 2024
    risk 0.20cvss 3.1epss 0.00

    Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user,…

  • CVE-2020-26173LowDec 18, 2020
    risk 0.20cvss 3.1epss 0.01

    An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.

  • CVE-2025-31963LowJan 7, 2026
    risk 0.19cvss 2.9epss 0.00

    Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.

  • CVE-2026-47038LowJul 21, 2026
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to…

  • CVE-2026-102363LowSep 29, 2026
    risk 0.17cvss 3.7epss 0.00

    mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill…

  • CVE-2026-40184LowApr 10, 2026
    risk 0.17cvss 3.7epss 0.00

    TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.

  • CVE-2026-33070LowMar 20, 2026
    risk 0.17cvss 3.7epss 0.00

    FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnerability in the deleteShareLink endpoint allows any unauthenticated user to delete arbitrary file share links by providing only the share token, causing denial…