CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,847 vulnerabilities with CWE-306
CVE-2026-47391
CRITICAL
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
CVSS 9.8
CVE-2026-47122
MEDIUM
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
CVSS 4.2
CVE-2026-57495
HIGH
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
CVE-2026-55626
HIGH
xrdp: No authentication required with Xvnc backend on RHEL 9
CVSS 8.0
CVE-2026-46555
HIGH
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVSS 7.7
CVE-2026-63429
HIGH
HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context
CVSS 8.6
CVE-2026-63757
HIGH
SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
CVSS 8.8
CVE-2026-16242
CRITICAL
Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
CVSS 9.4
CVE-2026-16210
HIGH
newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication
CVSS 7.3
CVE-2026-16209
HIGH
Gerapy Project Upload Endpoint views.py missing authentication
CVSS 7.3
CVE-2026-8505
CRITICAL
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
CVSS 9.8
CVE-2026-9103
CRITICAL
IBM Langflow OSS - Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
CVSS 9.8
CVE-2026-9202
CRITICAL
IBM Langflow OSS 1.0.0-1.10.0 - Unauthenticated User Registration to Remote Code Execution
CVSS 9.8
CVE-2026-63101
HIGH
Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint
CVSS 7.5
CVE-2026-12691
HIGH
Authentication Bypass in Vimesoft's Enterprise Video Platform
CVSS 7.5
CVE-2026-63098
MEDIUM
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVSS 5.3
CVE-2026-16015
MEDIUM
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
CVSS 6.3
CVE-2026-62241
CRITICAL
clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVSS 9.1
CVE-2026-6511
MEDIUM
Lenovo Smart Connect < 09.0.2.003.000 - Missing Authentication for Critical Function
CVSS 5.5
CVE-2026-63087
CRITICAL
Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
CVSS 9.8
CVE-2026-57206
HIGH
SimpleChat plugin validation endpoints missing authentication and authorization
CVSS 8.6
CVE-2026-45695
CRITICAL
Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
CVSS 9.8
CVE-2026-46339
CRITICAL
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVSS 10.0
CVE-2026-58658
HIGH
GPUStack Unauthenticated Information Disclosure via Worker Endpoints
CVSS 8.2
CVE-2026-53512
CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVSS 9.1
Details
Vulnerabilities
2,847
Exploit Likelihood
High