VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 86 of 169
  • CVE-2026-72605HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An…

  • CVE-2026-72688HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any…

  • CVE-2026-72586HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES,…

  • CVE-2026-55814HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2026-70559HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check. Any remote…

  • CVE-2026-69111HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected…

  • CVE-2026-8446HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .

  • CVE-2026-48911HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by…

  • CVE-2026-71241HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers,…

  • CVE-2026-68578HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary…

  • CVE-2026-65310HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.01

    ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values…

  • CVE-2026-28814HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

  • CVE-2026-62493HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-61141HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60988HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60894HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-60619HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60498HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET…

  • CVE-2026-60497HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise…

  • CVE-2026-60496HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Advanced Pricing). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via…