VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 44 of 167
  • CVE-2019-6538CriMar 25, 2019
    risk 0.61cvss 9.3epss 0.01

    The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D…

  • CVE-2019-6447HigJan 16, 2019
    risk 0.61cvss 8.1epss 0.64

    The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once,…

  • CVE-2026-16876CriSep 7, 2026
    risk 0.60cvss —epss 0.00

    An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

  • CVE-2026-57910CriAug 25, 2026
    risk 0.60cvss —epss 0.00

    Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

  • CVE-2026-77644CriAug 20, 2026
    risk 0.60cvss —epss 0.00

    A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

  • CVE-2026-71878CriAug 18, 2026
    risk 0.60cvss —epss 0.00

    Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

  • CVE-2026-71566CriAug 17, 2026
    risk 0.60cvss 9.3epss 0.00

    FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This…

  • CVE-2026-59506CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

  • CVE-2025-15681CriAug 10, 2026
    risk 0.60cvss —epss 0.00

    TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid…

  • CVE-2026-62241CriJul 17, 2026
    risk 0.60cvss 9.1epss 0.07

    clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a…

  • CVE-2026-48325CriJul 14, 2026
    risk 0.60cvss 9.3epss 0.01

    ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-46912CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-28766CriApr 3, 2026
    risk 0.60cvss 9.3epss 0.00

    A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

  • CVE-2026-3356CriMar 31, 2026
    risk 0.60cvss —epss 0.00

    The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design…

  • CVE-2026-33032CriMar 30, 2026
    risk 0.60cvss 9.8epss 0.36

    Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired()…

  • CVE-2026-2417CriMar 24, 2026
    risk 0.60cvss —epss 0.01

    A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

  • CVE-2026-26190CriFeb 13, 2026
    risk 0.60cvss 9.8epss 0.37

    Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from…

  • CVE-2026-1341CriFeb 3, 2026
    risk 0.60cvss —epss 0.01

    Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

  • CVE-2025-69970CriFeb 3, 2026
    risk 0.60cvss 9.3epss 0.00

    FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access…

  • CVE-2026-25137CriFeb 2, 2026
    risk 0.60cvss 9.1epss 0.10

    The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including…