CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,341)
page 164 of 168| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-61613 | Hig | 0.00 | — | 0.01 | Jul 15, 2026 | Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling… | ||
| CVE-2026-24259 | Med | 0.00 | 6.4 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | ||
| CVE-2026-24229 | Hig | 0.00 | 7.3 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to… | ||
| CVE-2026-50451 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50444 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-57969 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-50333 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49174 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-58319 | Cri | 0.00 | 9.1 | 0.01 | Jul 14, 2026 | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and… | ||
| CVE-2026-62327 | Cri | 0.00 | 9.1 | 0.01 | Jul 13, 2026 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint.… | ||
| CVE-2026-59801 | Cri | 0.00 | 9.8 | 0.03 | Jul 13, 2026 | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under… | ||
| CVE-2026-6847 | Cri | 0.00 | — | 0.01 | Jul 13, 2026 | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and… | ||
| CVE-2026-22096 | — | Cri | 0.00 | — | 0.01 | Jul 13, 2026 | The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints. | |
| CVE-2026-15491 | Hig | 0.00 | 7.3 | 0.01 | Jul 12, 2026 | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release… | ||
| CVE-2026-57476 | Med | 0.00 | 4.8 | 0.00 | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network… | ||
| CVE-2026-57475 | Med | 0.00 | 5.3 | 0.01 | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted… | ||
| CVE-2026-40006 | Hig | 0.00 | 7.5 | 0.01 | Jul 10, 2026 | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on… | ||
| CVE-2026-58123 | Cri | 0.00 | 9.8 | 0.05 | Jul 9, 2026 | Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell,… | ||
| CVE-2026-61344 | Med | 0.00 | 5.3 | 0.00 | Jul 9, 2026 | The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication. | ||
| CVE-2026-59726 | Cri | 0.00 | 10.0 | 0.03 | Jul 9, 2026 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to… |
- risk 0.00cvss —epss 0.01
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling…
- risk 0.00cvss 6.4epss 0.00
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- risk 0.00cvss 7.3epss 0.00
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to…
- risk 0.00cvss 7.1epss 0.00
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.01
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 8.8epss 0.01
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 7.8epss 0.00
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.1epss 0.00
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- risk 0.00cvss 9.1epss 0.01
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and…
- risk 0.00cvss 9.1epss 0.01
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint.…
- risk 0.00cvss 9.8epss 0.03
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under…
- risk 0.00cvss —epss 0.01
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and…
- risk 0.00cvss —epss 0.01
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.
- risk 0.00cvss 7.3epss 0.01
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release…
- risk 0.00cvss 4.8epss 0.00
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network…
- risk 0.00cvss 5.3epss 0.01
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted…
- risk 0.00cvss 7.5epss 0.01
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on…
- risk 0.00cvss 9.8epss 0.05
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell,…
- risk 0.00cvss 5.3epss 0.00
The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.
- risk 0.00cvss 10.0epss 0.03
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to…