CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-41899 MEDIUM
Coolify unauthenticated feedback endpoint allows Discord webhook abuse
CVSS 6.5
CVE-2026-42341 CRITICAL
FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
CVE-2026-42331 HIGH
FOSSBilling missing authorization in guest Invoice API endpoints
CVE-2026-53913 CRITICAL
Apache Camel Keycloak 4.18.3 and 4.21.0 - Remote Code Execution
CVSS 9.8
CVE-2026-14714 MEDIUM
zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
CVSS 6.5
CVE-2026-14622 HIGH
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
CVSS 7.3
CVE-2026-10054 HIGH
Eclipse Theia < 1.73.0 - Missing Origin Validation in WebSockets
CVSS 8.8
CVE-2026-4767 CRITICAL
Improper Access Control in TR7's WAF-ASP
CVSS 9.8
CVE-2026-13125 HIGH
GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability
CVSS 8.8
CVE-2026-58127 CRITICAL
PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service
CVSS 9.8
CVE-2026-58126 CRITICAL
PACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service
CVSS 9.8
CVE-2026-56286 HIGH
Capgo - Account Deletion Without Password Confirmation
CVSS 8.1
CVE-2026-58446 MEDIUM
Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP Endpoint
CVSS 6.5
CVE-2026-58375 HIGH
JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export
CVSS 7.5
CVE-2026-44949 HIGH
Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook
CVE-2026-14162 CRITICAL
Advantech|Hospital Quering Management - Missing Authentication
CVSS 9.8
CVE-2026-12819 CRITICAL
DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
CVE-2026-56782 CRITICAL
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
CVSS 9.8
CVE-2026-13546 HIGH
Feehi CMS REST API Endpoint articles missing authentication
CVSS 7.3
CVE-2026-50136 HIGH
Budibase < 3.39.3 - Unauthenticated S3 Presigned Upload URL Creation
CVSS 7.4
CVE-2026-13325 HIGH
Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces
CVSS 8.5
CVE-2026-43920 MEDIUM
FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution
CVE-2026-40702 CRITICAL
EVoke Systems EVoke CSMS Missing Authentication for Critical Function
CVSS 9.4
CVE-2026-54088 CRITICAL
File Browser < 2.63.6 - Pre-Authentication Remote Code Execution
CVE-2026-54040 MEDIUM
LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass
CVSS 5.9
Details
Vulnerabilities 2,847
Exploit Likelihood High