VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 67 of 150
  • CVE-2026-55196CriJun 17, 2026
    risk 0.52cvss 9.1epss 0.01

    Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST…

  • CVE-2026-53469CriJun 10, 2026
    risk 0.52cvss 9.1epss 0.00

    A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents,…

  • CVE-2026-0204HigApr 29, 2026
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

  • CVE-2026-41473CriApr 24, 2026
    risk 0.52cvss 9.1epss 0.01

    CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and…

  • CVE-2026-40289CriApr 14, 2026
    risk 0.52cvss 9.1epss 0.00

    PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on…

  • CVE-2026-34952CriApr 3, 2026
    risk 0.52cvss 9.1epss 0.00

    PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages…

  • CVE-2026-34758CriApr 2, 2026
    risk 0.52cvss 9.1epss 0.00

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version…

  • CVE-2026-27509HigFeb 26, 2026
    risk 0.52cvss 8.0epss 0.00

    Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join…

  • CVE-2026-26235HigFeb 12, 2026
    risk 0.52cvss 7.5epss 0.02

    JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. Attackers can send a single POST request to trigger the server reboot without requiring any authentication.

  • CVE-2026-22812HigJan 12, 2026
    risk 0.52cvss 8.8epss 0.17

    OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is…

  • CVE-2025-47357HigNov 4, 2025
    risk 0.52cvss 8.0epss 0.00

    Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.

  • CVE-2024-48920CriOct 17, 2024
    risk 0.52cvss 9.1epss 0.00

    PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system…

  • CVE-2023-51587HigMay 3, 2024
    risk 0.52cvss 7.5epss 0.36

    Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit…

  • CVE-2024-28179CriMar 20, 2024
    risk 0.52cvss 9.0epss 0.01

    Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access. Prior to versions 3.2.3 and 4.1.1, Jupyter Server Proxy did not check user authentication appropriately when proxying websockets,…

  • CVE-2023-43644CriSep 25, 2023
    risk 0.52cvss 9.1epss 0.01

    Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are…

  • CVE-2021-43483HigApr 8, 2022
    risk 0.52cvss 8.0epss 0.01

    An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.

  • CVE-2021-42539HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change.

  • CVE-2019-19142HigJan 17, 2020
    risk 0.52cvss 7.5epss 0.08

    Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.

  • CVE-2018-7357MedNov 14, 2018
    risk 0.52cvss 6.5epss 0.88

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.

  • CVE-2026-62777HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.