CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,842 vulnerabilities with CWE-306
CVE-2026-12562 HIGH
Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function
CVSS 8.8
CVE-2026-68502 CRITICAL
LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE
CVSS 9.8
CVE-2026-67594 CRITICAL
Spikster Missing Authentication via API Route Group
CVSS 9.8
CVE-2026-67208 CRITICAL
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVSS 9.8
CVE-2026-67349 HIGH
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
CVSS 7.5
CVE-2026-12722 HIGH
Authentication Bypass in FTC Software's E-Commerce Management Panel
CVSS 8.2
CVE-2026-54367 HIGH
CentreStack < 17.2 Unauthenticated API Authorization Bypass
CVSS 8.6
CVE-2026-54365 HIGH
CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dll
CVSS 7.5
CVE-2026-44101 CRITICAL
Phoenix Contact CHARX SEC-3150 - OCPP Reconfiguration Vulnerability
CVSS 9.8
CVE-2026-44100 CRITICAL
Phoenix Contact CHARX SEC-3150 - JupiCore Charging Point Reconfiguration Without Auth
CVSS 9.4
CVE-2026-44090 CRITICAL
Phoenix Contact CHARX SEC-3150 - Missing Authentication for MQTT Broker
CVSS 9.8
CVE-2026-47858 HIGH
Spring Tools Live Information Mode - JMX Remote Code Execution
CVSS 8.0
CVE-2026-13306 MEDIUM
Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
CVSS 4.3
CVE-2026-5057 HIGH
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability
CVSS 7.5
CVE-2026-67426 CRITICAL
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
CVSS 9.3
CVE-2026-14529 CRITICAL
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
CVSS 9.4
CVE-2026-60113 CRITICAL
NASA-AMMOS AIT-DSN < 2.2.2 - Missing Authentication in SLE API Routes
CVSS 9.8
CVE-2026-60112 CRITICAL
NASA-AMMOS AIT-GUI < 2.5.1 - Missing Authentication via Sessions.create()
CVSS 9.8
CVE-2026-62325 CRITICAL
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVSS 9.1
CVE-2026-14976 HIGH
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
CVSS 7.1
CVE-2026-14446 CRITICAL
IBM WebSphere Application Server is affected by a privilege escalation
CVSS 9.8
CVE-2026-16771 HIGH
At&t Arris BGW210‑700 < 2.7.7 - Missing Authentication for Critical Function
CVSS 8.8
CVE-2026-7187 HIGH
Improper Authentication in Universal Sotware's UKBS
CVSS 8.8
CVE-2026-12989 HIGH
Ghost Robotics Vision 60 APK 5.5.0 - Missing Authentication for Robot Control
CVE-2026-66006 MEDIUM
lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs
CVSS 5.3
Details
Vulnerabilities 2,842
Exploit Likelihood High