CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-47391 CRITICAL
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
CVSS 9.8
CVE-2026-47122 MEDIUM
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
CVSS 4.2
CVE-2026-57495 HIGH
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
CVE-2026-55626 HIGH
xrdp: No authentication required with Xvnc backend on RHEL 9
CVSS 8.0
CVE-2026-46555 HIGH
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVSS 7.7
CVE-2026-63429 HIGH
HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context
CVSS 8.6
CVE-2026-63757 HIGH
SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
CVSS 8.8
CVE-2026-16242 CRITICAL
Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
CVSS 9.4
CVE-2026-16210 HIGH
newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication
CVSS 7.3
CVE-2026-16209 HIGH
Gerapy Project Upload Endpoint views.py missing authentication
CVSS 7.3
CVE-2026-8505 CRITICAL
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
CVSS 9.8
CVE-2026-9103 CRITICAL
IBM Langflow OSS - Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
CVSS 9.8
CVE-2026-9202 CRITICAL
IBM Langflow OSS 1.0.0-1.10.0 - Unauthenticated User Registration to Remote Code Execution
CVSS 9.8
CVE-2026-63101 HIGH
Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint
CVSS 7.5
CVE-2026-12691 HIGH
Authentication Bypass in Vimesoft's Enterprise Video Platform
CVSS 7.5
CVE-2026-63098 MEDIUM
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVSS 5.3
CVE-2026-16015 MEDIUM
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
CVSS 6.3
CVE-2026-62241 CRITICAL
clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVSS 9.1
CVE-2026-6511 MEDIUM
Lenovo Smart Connect < 09.0.2.003.000 - Missing Authentication for Critical Function
CVSS 5.5
CVE-2026-63087 CRITICAL
Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
CVSS 9.8
CVE-2026-57206 HIGH
SimpleChat plugin validation endpoints missing authentication and authorization
CVSS 8.6
CVE-2026-45695 CRITICAL
Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
CVSS 9.8
CVE-2026-46339 CRITICAL
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVSS 10.0
CVE-2026-58658 HIGH
GPUStack Unauthenticated Information Disclosure via Worker Endpoints
CVSS 8.2
CVE-2026-53512 CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVSS 9.1
Details
Vulnerabilities 2,847
Exploit Likelihood High