CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-57475 MEDIUM
Deloitte AI Assist for Customer unauthenticated configuration write
CVSS 5.3
CVE-2026-56675 HIGH
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVSS 8.3
CVE-2026-38059 HIGH
ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function
CVSS 7.5
CVE-2026-40006 HIGH
Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
CVSS 7.5
CVE-2026-58123 CRITICAL
Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API
CVSS 9.8
CVE-2026-55605 MEDIUM
@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint
CVSS 5.3
CVE-2026-59148 HIGH
Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
CVSS 8.8
CVE-2026-0283 HIGH
PAN-OS LSVPN - Authentication Bypass
CVSS 7.2
CVE-2026-61344 MEDIUM
Superior Court of California Hearing Reminder Service unauthenticated information disclosure
CVSS 5.3
CVE-2026-59726 CRITICAL
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVSS 10.0
CVE-2026-59715 LOW
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVSS 3.1
CVE-2026-15192 MEDIUM
mettle sendportal APIv1 Webhooks mailjet missing authentication
CVSS 6.5
CVE-2026-31983 MEDIUM
Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
CVSS 5.3
CVE-2026-54776 MEDIUM
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVSS 4.4
CVE-2026-44025 HIGH
Fluentd: Exposure of Sensitive Information via Monitor Agent API
CVSS 7.5
CVE-2026-59822 HIGH
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVSS 8.2
CVE-2026-59804 MEDIUM
Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
CVSS 6.8
CVE-2026-15063 MEDIUM
Trustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabled
CVSS 6.3
CVE-2026-54061 CRITICAL
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
CVSS 9.1
CVE-2026-59705 CRITICAL
mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints
CVSS 9.8
CVE-2026-51937 HIGH
OneBlog 2.3.9 - Unauthenticated Sensitive Information Disclosure via RestApiController and Access Token Components
CVSS 7.5
CVE-2026-59706 CRITICAL
mem0 - Server-Side Request Forgery and Plaintext API Key Exposure via Unauthenticated Config Endpoints
CVSS 9.3
CVE-2026-58473 CRITICAL
Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
CVSS 9.1
CVE-2026-49471 HIGH
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
CVSS 8.3
CVE-2026-53647 MEDIUM
FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint
Details
Vulnerabilities 2,847
Exploit Likelihood High