VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 6 of 167
  • CVE-2026-83059CriSep 15, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to…

  • CVE-2026-83021CriSep 15, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2026-83020CriSep 15, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-71133CriSep 15, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-80462CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

  • CVE-2026-67277HigKEVSep 5, 2026
    risk 0.65cvss 8.2epss 0.01

    RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet…

  • CVE-2026-75754CriSep 4, 2026
    risk 0.65cvss —epss 0.00

    Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The…

  • CVE-2026-70352CriSep 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-82695CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to…

  • CVE-2026-82694CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2026-82693CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The…

  • CVE-2026-20357CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-58115CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to…

  • CVE-2026-63508CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-60365CriJul 21, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated…

  • CVE-2026-10577CriJul 14, 2026
    risk 0.65cvss —epss 0.00

    A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If…

  • CVE-2026-62422CriJul 14, 2026
    risk 0.65cvss 10.0epss 0.00

    In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

  • CVE-2026-54309CriJun 23, 2026
    risk 0.65cvss 10.0epss 0.01

    n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any…

  • CVE-2026-50242CriJun 19, 2026
    risk 0.65cvss 10.0epss 0.01

    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

  • CVE-2026-46846CriJun 17, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…