CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,361)
page 153 of 169| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-9195 | 0.09 | — | 0.81 | Jan 17, 2015 | Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic. | |||
| CVE-2014-4872 | 0.09 | — | 0.79 | Oct 10, 2014 | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2)… | |||
| CVE-2026-50608 | Low | 0.08 | — | 0.00 | Sep 17, 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized… | ||
| CVE-2022-3229 | Cri | 0.08 | 9.8 | 0.66 | Feb 6, 2023 | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated… | ||
| CVE-2020-12492 | — | Low | 0.07 | — | 0.00 | Nov 25, 2024 | Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information. | |
| CVE-2023-4506 | Low | 0.07 | 2.2 | 0.01 | Sep 27, 2023 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with… | ||
| CVE-2022-23944 | Cri | 0.06 | 9.1 | 0.79 | Jan 25, 2022 | User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | ||
| CVE-2009-1780 | 0.03 | — | 0.04 | May 22, 2009 | admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters. | |||
| CVE-2024-6842 | Hig | 0.02 | 7.5 | 0.31 | Mar 20, 2025 | In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be… | ||
| CVE-2007-0956 | 0.02 | — | 0.30 | Apr 6, 2007 | The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882. | |||
| CVE-2026-78154 | 0.00 | — | 0.00 | Aug 24, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The endpoint is public on purpose and the invitation code is the credential.… | |||
| CVE-2026-75501 | 0.00 | — | 0.01 | Aug 21, 2026 | Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment. | |||
| CVE-2026-67594 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing… | ||
| CVE-2026-67208 | Cri | 0.00 | 9.8 | 0.04 | Jul 30, 2026 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected… | ||
| CVE-2026-15978 | Hig | 0.00 | 7.5 | 0.01 | Jul 30, 2026 | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model… | ||
| CVE-2026-12722 | — | Hig | 0.00 | 8.2 | 0.00 | Jul 30, 2026 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2. | |
| CVE-2026-54367 | Hig | 0.00 | 8.6 | 0.00 | Jul 30, 2026 | CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId… | ||
| CVE-2026-54365 | Hig | 0.00 | 7.5 | 0.00 | Jul 30, 2026 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a… | ||
| CVE-2026-44101 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. | ||
| CVE-2026-44100 | Cri | 0.00 | 9.4 | 0.01 | Jul 30, 2026 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. |
- CVE-2014-9195Jan 17, 2015risk 0.09cvss —epss 0.81
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.
- CVE-2014-4872Oct 10, 2014risk 0.09cvss —epss 0.79
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2)…
- risk 0.08cvss —epss 0.00
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized…
- risk 0.08cvss 9.8epss 0.66
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated…
- risk 0.07cvss —epss 0.00
Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.
- risk 0.07cvss 2.2epss 0.01
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with…
- risk 0.06cvss 9.1epss 0.79
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
- CVE-2009-1780May 22, 2009risk 0.03cvss —epss 0.04
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.
- risk 0.02cvss 7.5epss 0.31
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be…
- CVE-2007-0956Apr 6, 2007risk 0.02cvss —epss 0.30
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
- CVE-2026-78154Aug 24, 2026risk 0.00cvss —epss 0.00
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The endpoint is public on purpose and the invitation code is the credential.…
- CVE-2026-75501Aug 21, 2026risk 0.00cvss —epss 0.01
Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.
- risk 0.00cvss 9.8epss 0.01
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing…
- risk 0.00cvss 9.8epss 0.04
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected…
- risk 0.00cvss 7.5epss 0.01
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model…
- risk 0.00cvss 8.2epss 0.00
Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.
- risk 0.00cvss 8.6epss 0.00
CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId…
- risk 0.00cvss 7.5epss 0.00
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a…
- risk 0.00cvss 9.8epss 0.01
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
- risk 0.00cvss 9.4epss 0.01
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.