CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-61613 HIGH
Cursor: Cloud Agent Browser Sandbox Escape
CVE-2026-48325 CRITICAL
Adobe ColdFusion 2025 - ColdFusion | Missing Authentication for Critical Function (CWE-306)
CVSS 9.3
CVE-2026-24259 MEDIUM
Nvidia TensorRT-LLM < v1.3.0 rc12 - Missing Authentication for Critical Function
CVSS 6.4
CVE-2026-24229 HIGH
Nvidia TensorRT-LLM < v1.3.0 rc16 - Missing Authentication for Critical Function
CVSS 7.3
CVE-2026-48252 HIGH
Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306)
CVSS 8.6
CVE-2026-47212 MEDIUM
Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-45755 MEDIUM
Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-45754 MEDIUM
Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
CVSS 5.3
CVE-2026-50451 HIGH
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVSS 7.1
CVE-2026-50444 HIGH
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-57969 HIGH
Azure CycleCloud Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-56164 MEDIUM KEV
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVSS 5.3
CVE-2026-50333 HIGH
Microsoft Windows 10 Version 1607 - Windows Spaceport.sys Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-49174 MEDIUM
Microsoft Windows 10 Version 1809 - DNS Client Tampering Vulnerability
CVSS 6.1
CVE-2026-10577 CRITICAL
Rockwell Automation 1715 Redundant IO – Access Control Vulnerability
CVE-2026-62422 CRITICAL
Jetbrains YouTrack - Missing Authentication for Critical Function
CVSS 10.0
CVE-2026-58319 CRITICAL
Apache Doris: Improper Authentication in Frontend HTTP API
CVSS 9.1
CVE-2026-15416 HIGH
Argo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpoint
CVSS 8.9
CVE-2026-62327 CRITICAL
9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
CVSS 9.1
CVE-2026-59801 CRITICAL
9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
CVSS 9.8
CVE-2026-6847 CRITICAL
Unauthenticated Remote Code Execution in ThemisNETPanel
CVE-2026-22096 CRITICAL
EVbee DC-80 - Missing Authentication for Webserver Endpoints
CVE-2026-15491 HIGH
RafyMrX TOKO-ONLINE-ROTI missing authentication
CVSS 7.3
CVE-2026-55884 CRITICAL
Tilt: Missing authentication on the network-exposed Tilt HUD server
CVE-2026-57476 MEDIUM
Deloitte AI Assist for Customer unauthenticated RAG corpus read and write
CVSS 4.8
Details
Vulnerabilities 2,847
Exploit Likelihood High