CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,488 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 1 of 70
- CVE-2025-34028CRITICALCVSS 10.0EG 10.0⚠ KEV2025-04-22
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in…
- CVE-2025-32433CRITICALCVSS 10.0EG 10.0⚠ KEV2025-04-16
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting …
- CVE-2020-6287CRITICALCVSS 10.0EG 10.0⚠ KEV2020-07-14
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions a…
- CVE-2010-5326CRITICALCVSS 10.0EG 10.0⚠ KEV2016-05-13
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in…
- CVE-2024-51567CRITICALCVSS 9.8EG 10.0⚠ KEV2024-10-29
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is …
- CVE-2026-72529CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-19
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
- CVE-2026-35273CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-11
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticate…
- CVE-2026-20253CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-10
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL s…
- CVE-2026-46817CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-28
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network…
- CVE-2026-41940CRITICALCVSS 9.8EG 9.8⚠ KEV2026-04-29
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- CVE-2026-39987CRITICALCVSS 9.8EG 9.8⚠ KEV2026-04-09
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell a…
- CVE-2026-33017CRITICALCVSS 9.8EG 9.8⚠ KEV2026-03-20
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the op…
- CVE-2026-24423CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-23
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the ma…
- CVE-2025-61757CRITICALCVSS 9.8EG 9.8⚠ KEV2025-10-21
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker…
- CVE-2025-3248CRITICALCVSS 9.8EG 9.8⚠ KEV2025-04-07
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
- CVE-2024-11680CRITICALCVSS 9.8EG 9.8⚠ KEV2024-11-26
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of th…
- CVE-2024-0012CRITICALCVSS 9.8EG 9.8⚠ KEV2024-11-18
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with t…
- CVE-2024-47575CRITICALCVSS 9.8EG 9.8⚠ KEV2024-10-23
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.…
- CVE-2024-5910CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-10
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration…
- CVE-2023-46747CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-26
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Softwar…
- CVE-2023-42793CRITICALCVSS 9.8EG 9.8⚠ KEV2023-09-19
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- CVE-2023-28461CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-15
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could t…
- CVE-2022-21587CRITICALCVSS 9.8EG 9.8⚠ KEV2022-10-18
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2022-40684CRITICALCVSS 9.8EG 9.8⚠ KEV2022-10-18
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 an…
- CVE-2022-1388CRITICALCVSS 9.8EG 9.8⚠ KEV2022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authen…
- CVE-2022-26501CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-17
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
- CVE-2022-26143CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-10
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive …
- CVE-2021-35587CRITICALCVSS 9.8EG 9.8⚠ KEV2022-01-19
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthentica…
- CVE-2022-23227CRITICALCVSS 9.8EG 9.8⚠ KEV2022-01-14
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE…
- CVE-2021-44077CRITICALCVSS 9.8EG 9.8⚠ KEV2021-11-29
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechn…
- CVE-2021-37415CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-01
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
- CVE-2020-10148CRITICALCVSS 9.8EG 9.8⚠ KEV2020-12-29
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may res…
- CVE-2020-13927CRITICALCVSS 9.8EG 9.8⚠ KEV2020-11-10
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requ…
- CVE-2020-3952CRITICALCVSS 9.8EG 9.8⚠ KEV2020-04-10
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
- CVE-2020-6207CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-10
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
- CVE-2025-0108CRITICALCVSS 9.1EG 9.1⚠ KEV2025-02-12
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interfa…
- CVE-2024-8956CRITICALCVSS 9.1EG 9.1⚠ KEV2024-09-17
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header.…
- CVE-2025-4008CRITICALCVSS 8.8EG 9.0⚠ KEV2025-05-21
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an e…
- CVE-2020-24363CRITICALCVSS 8.8EG 9.0⚠ KEV2020-08-31
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a …
- CVE-2019-9082CRITICALCVSS 8.8EG 9.0⚠ KEV2019-02-24
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
- CVE-2021-39144CRITICALCVSS 8.5EG 9.0⚠ KEV2021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stre…
- CVE-2026-67277CRITICALCVSS 8.2EG 9.0⚠ KEV2026-09-05
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an …
- CVE-2026-59822CRITICALCVSS 8.2EG 9.0⚠ KEV2026-07-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2…
- CVE-2025-24472CRITICALCVSS 8.1EG 9.0⚠ KEV2025-02-11
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior kn…
- CVE-2022-26925CRITICALCVSS 8.1EG 9.0⚠ KEV2022-05-10
Windows LSA Spoofing Vulnerability
- CVE-2025-48572CRITICALCVSS 7.8EG 9.0⚠ KEV2025-12-08
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-1603CRITICALCVSS 7.5EG 9.0⚠ KEV2026-02-10
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
- CVE-2023-27532CRITICALCVSS 7.5EG 9.0⚠ KEV2023-03-10
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
- CVE-2022-24990CRITICALCVSS 7.5EG 9.0⚠ KEV2023-02-07
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
- CVE-2023-21839CRITICALCVSS 7.5EG 9.0⚠ KEV2023-01-18
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated at…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →