CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,343 vulnerabilities with CWE-306
CVE-2026-6274 CRITICAL
Authentication Bypass in DTS Electronics' Redline WR3200
CVSS 9.8
CVE-2026-11238 MEDIUM
Google Chrome < 149.0.7827.53 - Information Disclosure via Malicious Extension
CVSS 5.9
CVE-2026-25550 CRITICAL
Seagull Software BarTender Unauthenticated RCE via .NET Remoting Service
CVSS 9.8
CVE-2026-50225 CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Account Creation Exhaustion
CVSS 9.1
CVE-2026-36603 HIGH
Mercusys AC12G (EU) V1 - Unauthenticated UPnP Port Forwarding Manipulation
CVSS 8.1
CVE-2026-10617 HIGH
nextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authentication
CVSS 7.3
CVE-2026-42074 CRITICAL
OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
CVSS 9.8
CVE-2026-0611 CRITICAL
Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting
CVSS 9.8
CVE-2026-24090 HIGH
Qualcomm Snapdragon HLOS - Boot Flow Modification via Partition Table
CVSS 7.1
CVE-2026-24088 HIGH
Qualcomm Snapdragon Boot - Unauthorized Bootloader Write Access
CVSS 8.2
CVE-2026-10283 MEDIUM
Bottelet DaybydayCRM <= 2.2.1 - Improper Authentication in Setting Handler
CVSS 6.3
CVE-2026-10281 HIGH
Enderfga claw-orchestrator <= 3.5.5 - Missing Authentication in EmbeddedServer API Endpoint
CVSS 7.3
CVE-2026-44211 CRITICAL
Cline Kanban Server <=2.13.0 - Cross-Origin WebSocket Hijacking
CVSS 9.6
CVE-2026-25599 MEDIUM
Missing authentication and clear‑text data transmission affecting Orca heat pumps
CVSS 6.3
CVE-2026-10243 HIGH
code-projects Smart Parking System Admin Endpoint missing authentication
CVSS 7.3
CVE-2026-9051 CRITICAL
NI SystemLink Enterprise <= 2026-04 - Authentication Bypass
CVSS 9.1
CVE-2026-44649 CRITICAL
SillyTavern: Authentication Bypass via SSO Header Injection
CVSS 9.8
CVE-2026-5768 HIGH
Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical Function
CVSS 8.8
CVE-2026-45577 MEDIUM
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
CVE-2026-45610 MEDIUM
WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
CVSS 5.7
CVE-2026-49195 HIGH
Predator Connect W6x: unauthenticated Debug Service
CVSS 8.8
CVE-2026-8732 CRITICAL
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
CVSS 9.8
CVE-2026-46840 CRITICAL
Oracle REST Data Services 24.2.0-26.1.0 - Unauthenticated Remote Code Execution via HTTPS
CVSS 10.0
CVE-2026-46827 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution in Self Service Manager
CVSS 8.8
CVE-2026-46826 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations
CVSS 8.8
Details
Vulnerabilities 2,343
Exploit Likelihood High