CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,844 vulnerabilities with CWE-306
CVE-2026-65311
MEDIUM
ANDRITZ HIPASE-250 - Missing Authentication for Logging-Configuration Endpoint
CVSS 5.3
CVE-2026-65310
HIGH
ANDRITZ HIPASE-250 - Missing Authentication and Permissive CORS Policy
CVSS 7.5
CVE-2026-12562
HIGH
Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function
CVSS 8.8
CVE-2026-68502
CRITICAL
LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE
CVSS 9.8
CVE-2026-67594
CRITICAL
Spikster Missing Authentication via API Route Group
CVSS 9.8
CVE-2026-67208
CRITICAL
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVSS 9.8
CVE-2026-67349
HIGH
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
CVSS 7.5
CVE-2026-12722
HIGH
Authentication Bypass in FTC Software's E-Commerce Management Panel
CVSS 8.2
CVE-2026-54367
HIGH
CentreStack < 17.2 Unauthenticated API Authorization Bypass
CVSS 8.6
CVE-2026-54365
HIGH
CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dll
CVSS 7.5
CVE-2026-44101
CRITICAL
Phoenix Contact CHARX SEC-3150 - OCPP Reconfiguration Vulnerability
CVSS 9.8
CVE-2026-44100
CRITICAL
Phoenix Contact CHARX SEC-3150 - JupiCore Charging Point Reconfiguration Without Auth
CVSS 9.4
CVE-2026-44090
CRITICAL
Phoenix Contact CHARX SEC-3150 - Missing Authentication for MQTT Broker
CVSS 9.8
CVE-2026-47858
HIGH
Spring Tools Live Information Mode - JMX Remote Code Execution
CVSS 8.0
CVE-2026-13306
MEDIUM
Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
CVSS 4.3
CVE-2026-5057
HIGH
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability
CVSS 7.5
CVE-2026-67426
CRITICAL
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
CVSS 9.3
CVE-2026-14529
CRITICAL
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
CVSS 9.4
CVE-2026-60113
CRITICAL
NASA-AMMOS AIT-DSN < 2.2.2 - Missing Authentication in SLE API Routes
CVSS 9.8
CVE-2026-60112
CRITICAL
NASA-AMMOS AIT-GUI < 2.5.1 - Missing Authentication via Sessions.create()
CVSS 9.8
CVE-2026-62325
CRITICAL
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVSS 9.1
CVE-2026-14976
HIGH
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
CVSS 7.1
CVE-2026-14446
CRITICAL
IBM WebSphere Application Server is affected by a privilege escalation
CVSS 9.8
CVE-2026-16771
HIGH
At&t Arris BGW210‑700 < 2.7.7 - Missing Authentication for Critical Function
CVSS 8.8
CVE-2026-7187
HIGH
Improper Authentication in Universal Sotware's UKBS
CVSS 8.8
Details
Vulnerabilities
2,844
Exploit Likelihood
High