CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,982)
page 69 of 150| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-9815 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2025 | A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the… | ||
| CVE-2025-53789 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-41686 | — | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access. | |
| CVE-2024-9062 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2025 | The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. Archify follows the "factored applications" model, delegating privileged… | ||
| CVE-2024-50630 | Hig | 0.51 | 7.5 | 0.23 | Mar 19, 2025 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors. | ||
| CVE-2021-26280 | — | Hig | 0.51 | 7.9 | 0.00 | Dec 17, 2024 | Locally installed application can bypass the permission check and perform system operations that require permission. | |
| CVE-2024-47574 | Hig | 0.51 | 7.8 | 0.00 | Nov 13, 2024 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed… | ||
| CVE-2022-23862 | Hig | 0.51 | 7.8 | 0.00 | Oct 22, 2024 | A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is… | ||
| CVE-2024-8012 | Hig | 0.51 | 7.8 | 0.00 | Sep 10, 2024 | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | ||
| CVE-2024-7125 | Hig | 0.51 | 7.8 | 0.00 | Aug 27, 2024 | Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01. | ||
| CVE-2024-2860 | Hig | 0.51 | 7.8 | 0.00 | May 8, 2024 | The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database. | ||
| CVE-2024-26235 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2022-43555 | Hig | 0.51 | 7.8 | 0.00 | Nov 3, 2023 | Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability | ||
| CVE-2022-43554 | Hig | 0.51 | 7.8 | 0.00 | Nov 3, 2023 | Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability | ||
| CVE-2023-4516 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content. | ||
| CVE-2023-31132 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document… | ||
| CVE-2023-36347 | Hig | 0.51 | 7.5 | 0.34 | Jun 30, 2023 | A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data. | ||
| CVE-2023-2827 | Hig | 0.51 | 7.9 | 0.00 | Jun 13, 2023 | SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the… | ||
| CVE-2022-29957 | Hig | 0.51 | 7.8 | 0.00 | Jul 26, 2022 | The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk… | ||
| CVE-2022-28809 | Hig | 0.51 | 7.8 | 0.00 | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the… |
- risk 0.51cvss 7.8epss 0.00
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the…
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access.
- risk 0.51cvss 7.8epss 0.00
The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. Archify follows the "factored applications" model, delegating privileged…
- risk 0.51cvss 7.5epss 0.23
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
- risk 0.51cvss 7.9epss 0.00
Locally installed application can bypass the permission check and perform system operations that require permission.
- risk 0.51cvss 7.8epss 0.00
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed…
- risk 0.51cvss 7.8epss 0.00
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is…
- risk 0.51cvss 7.8epss 0.00
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
- risk 0.51cvss 7.8epss 0.00
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.
- risk 0.51cvss 7.8epss 0.00
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
- risk 0.51cvss 7.8epss 0.00
Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
- risk 0.51cvss 7.8epss 0.00
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
- risk 0.51cvss 7.8epss 0.00
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document…
- risk 0.51cvss 7.5epss 0.34
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
- risk 0.51cvss 7.9epss 0.00
SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the…
- risk 0.51cvss 7.8epss 0.00
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the…