VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 85 of 169
  • CVE-2026-84452HigSep 2, 2026
    risk 0.49cvss —epss 0.02

    Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the…

  • CVE-2026-18771HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.

  • CVE-2026-75133HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication.…

  • CVE-2026-82641HigAug 30, 2026
    risk 0.49cvss 8.6epss 0.01

    Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog…

  • CVE-2026-76640HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc…

  • CVE-2026-55539HigAug 25, 2026
    risk 0.49cvss 8.6epss 0.01

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete jobs using operator credentials. The fix adds…

  • CVE-2026-55534HigAug 25, 2026
    risk 0.49cvss 8.6epss 0.00

    PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even…

  • CVE-2026-67578HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.01

    FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.

  • CVE-2026-34741HigAug 21, 2026
    risk 0.49cvss 8.6epss 0.01

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed…

  • CVE-2026-49217HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided…

  • CVE-2025-52182HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.

  • CVE-2026-14952HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track…

  • CVE-2026-76355HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.01

    In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on. The vulnerability does not…

  • CVE-2026-19875HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.

  • CVE-2026-70973HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access…

  • CVE-2026-70930HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60975HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2026-60769HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-60765HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps -…

  • CVE-2026-75479HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and…