CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,361)
page 80 of 169| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54158 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2025 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors. | ||
| CVE-2025-34190 | Hig | 0.51 | 7.8 | 0.00 | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (macOS/Linux client deployments) are vulnerable to an authentication bypass in PrinterInstallerClientService. The service requires root privileges… | ||
| CVE-2025-10672 | Hig | 0.51 | 7.8 | 0.00 | Sep 18, 2025 | A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCService.swift of the component com.collweb.AIBatteryHelper. The manipulation results in missing authentication. The attack requires… | ||
| CVE-2025-9815 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2025 | A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the… | ||
| CVE-2025-53789 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-41686 | — | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access. | |
| CVE-2024-9062 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2025 | The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. Archify follows the "factored applications" model, delegating privileged… | ||
| CVE-2024-50630 | Hig | 0.51 | 7.5 | 0.25 | Mar 19, 2025 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors. | ||
| CVE-2021-26280 | — | Hig | 0.51 | 7.9 | 0.00 | Dec 17, 2024 | Locally installed application can bypass the permission check and perform system operations that require permission. | |
| CVE-2024-47574 | Hig | 0.51 | 7.8 | 0.00 | Nov 13, 2024 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed… | ||
| CVE-2022-23862 | Hig | 0.51 | 7.8 | 0.00 | Oct 22, 2024 | A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is… | ||
| CVE-2024-8012 | Hig | 0.51 | 7.8 | 0.00 | Sep 10, 2024 | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | ||
| CVE-2024-7125 | Hig | 0.51 | 7.8 | 0.00 | Aug 27, 2024 | Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01. | ||
| CVE-2024-2860 | Hig | 0.51 | 7.8 | 0.00 | May 8, 2024 | The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database. | ||
| CVE-2024-26235 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2022-43555 | Hig | 0.51 | 7.8 | 0.00 | Nov 3, 2023 | Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability | ||
| CVE-2022-43554 | Hig | 0.51 | 7.8 | 0.00 | Nov 3, 2023 | Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability | ||
| CVE-2023-4516 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content. | ||
| CVE-2023-31132 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document… | ||
| CVE-2023-36347 | Hig | 0.51 | 7.5 | 0.34 | Jun 30, 2023 | A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data. |
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
- risk 0.51cvss 7.8epss 0.00
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (macOS/Linux client deployments) are vulnerable to an authentication bypass in PrinterInstallerClientService. The service requires root privileges…
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCService.swift of the component com.collweb.AIBatteryHelper. The manipulation results in missing authentication. The attack requires…
- risk 0.51cvss 7.8epss 0.00
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the…
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access.
- risk 0.51cvss 7.8epss 0.00
The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. Archify follows the "factored applications" model, delegating privileged…
- risk 0.51cvss 7.5epss 0.25
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
- risk 0.51cvss 7.9epss 0.00
Locally installed application can bypass the permission check and perform system operations that require permission.
- risk 0.51cvss 7.8epss 0.00
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed…
- risk 0.51cvss 7.8epss 0.00
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is…
- risk 0.51cvss 7.8epss 0.00
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
- risk 0.51cvss 7.8epss 0.00
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.
- risk 0.51cvss 7.8epss 0.00
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
- risk 0.51cvss 7.8epss 0.00
Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
- risk 0.51cvss 7.8epss 0.00
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
- risk 0.51cvss 7.8epss 0.00
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document…
- risk 0.51cvss 7.5epss 0.34
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.