VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 55 of 167
  • CVE-2026-71067HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile…

  • CVE-2026-70956HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access…

  • CVE-2026-70940HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-70918HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-60967HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…

  • CVE-2026-60879HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise…

  • CVE-2026-60751HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps -…

  • CVE-2026-60731HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise…

  • CVE-2026-60722HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to…

  • CVE-2026-60716HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to…

  • CVE-2026-75854CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on…

  • CVE-2026-75852CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.00

    ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

  • CVE-2026-73673HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher.…

  • CVE-2026-72776CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard…

  • CVE-2026-49827CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.00

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open…

  • CVE-2026-49819CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any…

  • CVE-2026-65941HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • CVE-2026-66875HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a…

  • CVE-2026-64921HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-72920CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,…