CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,492 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 12 of 70
- CVE-2026-22207CRITICALCVSS 9.8EG 9.82026-02-26
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send r…
- CVE-2026-2624CRITICALCVSS 9.8EG 9.82026-02-25
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): f…
- CVE-2025-14577CRITICALCVSS 9.8EG 9.82026-02-24
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue …
- CVE-2026-3053CRITICALCVSS 9.8EG 9.82026-02-24
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation …
- CVE-2025-30410CRITICALCVSS 9.8EG 9.82026-02-20
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) b…
- CVE-2025-8350CRITICALCVSS 9.8EG 9.82026-02-19
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: f…
- CVE-2026-1670CRITICALCVSS 9.8EG 9.82026-02-17
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
- CVE-2026-26190CRITICALCVSS 9.8EG 9.82026-02-13
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable de…
- CVE-2026-1729CRITICALCVSS 9.8EG 9.82026-02-12
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_use…
- CVE-2026-25084CRITICALCVSS 9.8EG 9.82026-02-11
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
- CVE-2026-24789CRITICALCVSS 9.8EG 9.82026-02-11
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
- CVE-2026-2249CRITICALCVSS 9.8EG 9.82026-02-11
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with…
- CVE-2026-2248CRITICALCVSS 9.8EG 9.82026-02-11
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with…
- CVE-2025-8025CRITICALCVSS 9.8EG 9.82026-02-11
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dinosoft ERP: from < 3.0.1…
- CVE-2026-25938CRITICALCVSS 9.8EG 9.82026-02-09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the…
- CVE-2026-25895CRITICALCVSS 9.8EG 9.82026-02-09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affe…
- CVE-2026-25848CRITICALCVSS 9.8EG 9.82026-02-09
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
- CVE-2026-2165CRITICALCVSS 9.8EG 9.82026-02-08
A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument em…
- CVE-2026-25505CRITICALCVSS 9.8EG 9.82026-02-04
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This …
- CVE-2025-69981CRITICALCVSS 9.8EG 9.82026-02-03
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to o…
- CVE-2022-50981CRITICALCVSS 9.8EG 9.82026-02-02
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.
- CVE-2026-1453CRITICALCVSS 9.8EG 9.82026-01-29
A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative contr…
- CVE-2021-47891CRITICALCVSS 9.8EG 9.82026-01-23
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending speciall…
- CVE-2026-1364CRITICALCVSS 9.8EG 9.82026-01-23
IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system administrative functionalities.
- CVE-2026-24124CRITICALCVSS 9.8EG 9.82026-01-22
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/v1/jobs) lack JWT authentication middleware and RBAC authorization checks in the routing c…
- CVE-2025-54816CRITICALCVSS 9.8EG 9.82026-01-22
This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to…
- CVE-2026-23944CRITICALCVSS 9.8EG 9.82026-01-19
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be proxied to remote environment agents, allowing access to remote environment resources without …
- CVE-2026-23744CRITICALCVSS 9.8EG 9.82026-01-16
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the ins…
- CVE-2025-62582CRITICALCVSS 9.8EG 9.82026-01-16
Delta Electronics DIAView has multiple vulnerabilities.
- CVE-2026-22238CRITICALCVSS 9.8EG 9.82026-01-14
The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to c…
- CVE-2023-54335CRITICALCVSS 9.8EG 9.82026-01-13
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands…
- CVE-2025-14346CRITICALCVSS 9.8EG 9.82026-01-05
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulat…
- CVE-2025-15026CRITICALCVSS 9.8EG 9.82026-01-05
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 …
- CVE-2026-21446CRITICALCVSS 9.8EG 9.82026-01-02
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessi…
- CVE-2019-25240CRITICALCVSS 9.8EG 9.82025-12-24
Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequ…
- CVE-2019-25236CRITICALCVSS 9.8EG 9.82025-12-24
iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests t…
- CVE-2018-25134CRITICALCVSS 9.8EG 9.82025-12-24
Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by send…
- CVE-2025-65856CRITICALCVSS 9.8EG 9.82025-12-22
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF imp…
- CVE-2023-53968CRITICALCVSS 9.8EG 9.82025-12-22
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorize…
- CVE-2023-53964CRITICALCVSS 9.8EG 9.82025-12-22
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with…
- CVE-2025-12049CRITICALCVSS 9.8EG 9.82025-12-22
Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or p…
- CVE-2025-63389CRITICALCVSS 9.8EG 9.82025-12-18
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to…
- CVE-2025-43428CRITICALCVSS 9.8EG 9.82025-12-17
A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Photos in the Hidden Photos Album may be viewed without authentication.
- CVE-2020-36892CRITICALCVSS 9.8EG 9.82025-12-10
Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate…
- CVE-2023-53774CRITICALCVSS 9.8EG 9.82025-12-09
MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV systems. Attackers can send crafted SVDRP commands through the svdrpsend.sh script to exec…
- CVE-2023-53771CRITICALCVSS 9.8EG 9.82025-12-09
MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PA…
- CVE-2021-47731CRITICALCVSS 9.8EG 9.82025-12-09
Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'S…
- CVE-2025-27020CRITICALCVSS 9.8EG 9.82025-12-08
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.
- CVE-2025-27019CRITICALCVSS 9.8EG 9.82025-12-08
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
- CVE-2025-59695CRITICALCVSS 9.8EG 9.82025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). Thi…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →