VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 77 of 169
  • CVE-2017-12720HigFeb 15, 2018
    risk 0.53cvss 8.1epss 0.02

    An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump does not require authentication if the pump is configured to allow FTP connections.

  • CVE-2026-102361CriSep 29, 2026
    risk 0.52cvss 9.1epss 0.00

    mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without…

  • CVE-2026-54767CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.01

    WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source…

  • CVE-2026-54670CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.01

    WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive…

  • CVE-2026-61594CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.00

    djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django…

  • CVE-2026-92720CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.01

    Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and register malicious webhooks to intercept pipeline events or…

  • CVE-2026-92717CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.01

    Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and…

  • CVE-2026-77974HigSep 9, 2026
    risk 0.52cvss 8.0epss 0.00

    After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.

  • CVE-2026-85667CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit…

  • CVE-2026-81098CriAug 27, 2026
    risk 0.52cvss 9.1epss 0.01

    The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not…

  • CVE-2026-81094CriAug 27, 2026
    risk 0.52cvss 9.1epss 0.01

    The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when…

  • CVE-2026-55640CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults…

  • CVE-2026-73842CriAug 13, 2026
    risk 0.52cvss 9.0epss 0.00

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token,…

  • CVE-2026-72748CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.01

    AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust…

  • CVE-2026-15581HigAug 10, 2026
    risk 0.52cvss 8.0epss 0.00

    A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations,…

  • CVE-2026-47858HigJul 30, 2026
    risk 0.52cvss 8.0epss 0.00

    Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for…

  • CVE-2026-62325CriJul 28, 2026
    risk 0.52cvss 9.1epss 0.01

    goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication…

  • CVE-2026-53512CriJul 15, 2026
    risk 0.52cvss 9.1epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without…

  • CVE-2026-54061CriJul 8, 2026
    risk 0.52cvss 9.1epss 0.01

    Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open…

  • CVE-2026-58473CriJul 7, 2026
    risk 0.52cvss 9.1epss 0.01

    Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers…