VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 79 of 169
  • CVE-2018-7357MedNov 14, 2018
    risk 0.52cvss 6.5epss 0.88

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.

  • CVE-2026-69528HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62777HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61367HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61365HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61364HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61356HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42976HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-59913HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-60600HigJul 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft…

  • CVE-2026-15416HigJul 14, 2026
    risk 0.51cvss 8.9epss 0.00

    A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached…

  • CVE-2026-48989HigJun 17, 2026
    risk 0.51cvss —epss 0.01

    Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same…

  • CVE-2026-9045HigJun 10, 2026
    risk 0.51cvss 7.8epss 0.00

    During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

  • CVE-2026-50512HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-0247HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.

  • CVE-2026-26160HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26159HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-33788HigApr 9, 2026
    risk 0.51cvss 7.8epss 0.00

    A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local…

  • CVE-2026-24062HigMar 18, 2026
    risk 0.51cvss 7.8epss 0.00

    The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege…

  • CVE-2025-59516HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.