VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 72 of 169
  • CVE-2026-65105HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.00

    NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

  • CVE-2026-71068HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-70924HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access…

  • CVE-2026-70805HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-61307HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access…

  • CVE-2026-60831HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-60742HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-19426HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.01

    POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

  • CVE-2026-58071HigAug 4, 2026
    risk 0.53cvss —epss 0.00

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.

  • CVE-2026-24079HigAug 4, 2026
    risk 0.53cvss 8.1epss 0.00

    Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

  • CVE-2026-67610HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.00

    OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks…

  • CVE-2026-67426CriJul 29, 2026
    risk 0.53cvss 9.3epss 0.01

    Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST…

  • CVE-2026-63765HigJul 23, 2026
    risk 0.53cvss 8.2epss 0.01

    Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account…

  • CVE-2026-61225HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP…

  • CVE-2026-61170HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. …

  • CVE-2026-60810HigJul 21, 2026
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2026-60674HigJul 21, 2026
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2026-60670HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via…

  • CVE-2026-60621HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-55884CriJul 10, 2026
    risk 0.53cvss —epss 0.01

    Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated…