CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-54036 MEDIUM
LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification
CVSS 5.3
CVE-2026-4522 MEDIUM
Hypr Passwordless < 11.1.1 - Missing Authentication for Critical Function
CVE-2026-12490 HIGH
Bypass of client certificate verification with transfer over TLS
CVSS 7.5
CVE-2026-54068 MEDIUM
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
CVSS 5.9
CVE-2026-33543 CRITICAL
FOSSBilling: Authentication bypass allows unauthenticated administrator creation
CVE-2026-1840 HIGH
Missing authentication for critical function in Hubbell Aclara Metrum Cellular Web Interface
CVSS 7.5
CVE-2026-49980 CRITICAL
Rclone 1.46.0 to < 1.74.3 - Unauthenticated Command Execution via rc-serve
CVSS 9.8
CVE-2026-13164 HIGH
Unauthenticated self-registration in MailerUp allows access to stored email data
CVE-2026-56270 HIGH
Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint
CVSS 7.5
CVE-2026-56262 MEDIUM
Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server
CVSS 6.5
CVE-2026-54317 HIGH
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
CVSS 7.6
CVE-2026-55450 CRITICAL
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVSS 9.3
CVE-2026-13007 HIGH
Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
CVSS 7.5
CVE-2026-54309 CRITICAL
n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVSS 10.0
CVE-2026-27604 CRITICAL
FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions
CVE-2026-10711 HIGH
RCE in Akınsoft's CafePlus
CVSS 8.8
CVE-2026-56321 MEDIUM
Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint
CVSS 5.3
CVE-2026-41047 MEDIUM
Information leak via “diff” methods in qSnapper
CVSS 5.5
CVE-2026-6673 MEDIUM
Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install
CVSS 6.4
CVE-2026-56299 MEDIUM
Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint
CVSS 5.3
CVE-2026-12795 HIGH
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
CVSS 7.3
CVE-2026-56346 MEDIUM
AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint
CVSS 6.5
CVE-2026-9142 CRITICAL
NI grpc-device <= 2.17.0 - Insecure Default Credentials
CVSS 9.1
CVE-2026-49357 HIGH
Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
CVE-2026-50242 CRITICAL
Jetbrains Hub - Missing Authentication for Critical Function
CVSS 10.0
Details
Vulnerabilities 2,847
Exploit Likelihood High