CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,847 vulnerabilities with CWE-306
CVE-2026-12046 CRITICAL
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
CVSS 9.0
CVE-2026-54130 CRITICAL
M365 Copilot Information Disclosure Vulnerability
CVSS 9.8
CVE-2026-49257 CRITICAL
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
CVSS 10.0
CVE-2026-54103 CRITICAL
U.S. GAO EPDS and CBCA EDS unauthenticated password change
CVSS 9.8
CVE-2026-12527 MEDIUM
Shenzhen Liandian Communication Technology LTD V380 IP Camera / AppFHE1 V1.0.6.0 - Missing Authentication for Critical Function
CVE-2026-48989 HIGH
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
CVE-2026-48814 CRITICAL
Network-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)
CVSS 9.1
CVE-2026-55196 CRITICAL
Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass
CVSS 9.1
CVE-2026-53869 HIGH
Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints
CVSS 7.5
CVE-2026-30799 HIGH
RTI Connext Professional Security Plugins - Identity Spoofing
CVSS 8.1
CVE-2026-2675 MEDIUM
RTI Connext Professional Security Plugins - Source Spoofing
CVSS 6.5
CVE-2026-35065 HIGH
Dell PowerFlex - Missing Authentication for Critical Function
CVSS 8.8
CVE-2026-12199 HIGH
Unauthenticated Denial of Service in nltk.app.wordnet_app
CVSS 7.5
CVE-2026-46973 HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46972 HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46966 HIGH
Oracle Universal Work Queue 12.2.3-12.2.15 - Remote Code Execution via Work Provider
CVSS 7.5
CVE-2026-46965 HIGH
Oracle Universal Work Queue 12.2.3-12.2.15 - Remote Code Execution via Work Provider
CVSS 8.8
CVE-2026-46964 CRITICAL
Oracle Universal Work Queue 12.2.3-12.2.15 - Remote Code Execution via Work Provider
CVSS 9.9
CVE-2026-46962 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46961 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-46959 HIGH
Oracle Subledger Accounting 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46958 HIGH
Oracle Subledger Accounting 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-46952 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46951 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46942 HIGH
Oracle Process Manufacturing Process Planning 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
Details
Vulnerabilities 2,847
Exploit Likelihood High