CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,847 vulnerabilities with CWE-306
CVE-2026-35274
HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Unauthorized Data Access via Deployment Package
CVSS 8.2
CVE-2026-35267
HIGH
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Code Execution via REST WebServices
CVSS 8.8
CVE-2026-35265
HIGH
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-0647
HIGH
Rockwell FLEX I/O 1794-AENTR v2.012 - Unauthenticated Password Change
CVE-2026-12183
CRITICAL
Nefteprodukttekhnika LLC Buk Ts-g Gas Station Automation System < 2.10.2 - Improper Authentication
CVSS 9.8
CVE-2026-53868
HIGH
Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion
CVSS 7.5
CVE-2026-50287
HIGH
Missing Authentication for Critical Function in @agenticmail/mcp
CVE-2026-53981
HIGH
Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism
CVSS 7.6
CVE-2026-50085
HIGH
Aqara Board IoT insecure debug API
CVSS 8.6
CVE-2026-50082
MEDIUM
Aqara Developer Portal insecure authentication token
CVSS 6.5
CVE-2026-8694
MEDIUM
Improper access control on the API documentation endpoint in PowerShell Universal
CVSS 5.3
CVE-2026-11848
MEDIUM
IEI Integration Corp| iRM-IEI Remote Management - Missing Authentication
CVSS 5.3
CVE-2026-11535
CRITICAL
Vivo PcSuite - Missing Authentication for Critical Function
CVE-2026-50245
HIGH
Brickcom Cameras Missing Authentication for Critical Function
CVSS 7.7
CVE-2026-49973
CRITICAL
Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings
CVSS 9.4
CVE-2026-35273
CRITICAL
KEV
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via Updates Environment Management
CVSS 9.8
CVE-2026-46612
HIGH
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
CVSS 8.8
CVE-2026-20253
CRITICAL
KEV
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
CVSS 9.8
CVE-2026-45567
HIGH
Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVSS 8.3
CVE-2026-9045
HIGH
Lenovo Accessories And Display Manager For Enterprise < 1.0.9 - Missing Authentication for Critical Function
CVSS 7.8
CVE-2026-8335
HIGH
Aix-DB <= 1.2.4 - Missing Authentication on LLM SQL Query Endpoint
CVE-2026-53469
CRITICAL
Migration-planner: unprotected delete endpoint wipes all tenant data
CVSS 9.1
CVE-2026-50512
HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-9212
HIGH
Insufficient authentication and input validation in certain NETGEAR products
CVSS 8.0
CVE-2026-50507
MEDIUM
Microsoft Windows 10 Version 1607 - Windows BitLocker Security Feature Bypass Vulnerability
CVSS 6.8
Details
Vulnerabilities
2,847
Exploit Likelihood
High