CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,205 vulnerabilities with CWE-306
CVE-2026-34160 HIGH
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
CVSS 8.6
CVE-2026-33715 HIGH
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
CVSS 7.2
CVE-2026-26160 HIGH
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26159 HIGH
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40289 CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CVSS 9.1
CVE-2026-4810 CRITICAL
Remote Code Execution in Google Agent Development Kit (ADK)
CVE-2026-6129 HIGH
zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication
CVSS 7.3
CVE-2026-6126 HIGH
zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication
CVSS 7.3
CVE-2026-5724 MEDIUM
Missing Authentication on Streaming gRPC Replication Endpoint
CVE-2026-40184 LOW
Unauthenticated Access to Uploaded Files in TREK
CVSS 3.7
CVE-2026-5777 HIGH
Security Misconfiguration Vulnerability in Atom 3x Projector
CVE-2026-39848 MEDIUM
Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
CVSS 6.5
CVE-2026-33788 HIGH
Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs
CVSS 7.8
CVE-2026-4436 HIGH
GPL Odorizers GPL750 Missing Authentication for Critical Function
CVSS 8.6
CVE-2026-39987 CRITICAL KEV
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
CVE-2026-39393 HIGH
Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms
CVSS 8.1
CVE-2026-5300 MEDIUM
Missing Authentication for Critical Function in coolercontrold
CVSS 5.9
CVE-2026-39363 HIGH
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
CVSS 7.5
CVE-2026-35584 MEDIUM
FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration
CVSS 6.5
CVE-2026-35523 HIGH
Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocol
CVSS 7.5
CVE-2026-22679 CRITICAL
Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
CVSS 9.8
CVE-2026-1900 MEDIUM
Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update
CVSS 6.5
CVE-2026-35450 MEDIUM
WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php
CVSS 5.3
CVE-2026-5676 HIGH
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
CVSS 7.3
CVE-2026-26027 HIGH
GLPI has an Unauthenticated Stored XSS via inventory
CVSS 7.5
Details
Vulnerabilities 2,205
Exploit Likelihood High