CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,343 vulnerabilities with CWE-306
CVE-2026-42864 CRITICAL
FireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theft
CVSS 9.9
CVE-2026-44413 HIGH
JetBrains TeamCity - Authenticated Server API Unauthorized Access
CVSS 8.2
CVE-2026-42856 HIGH
Network-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool calls
CVE-2026-42312 MEDIUM
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification
CVSS 6.8
CVE-2026-42569 CRITICAL
phpvms: /importer authorization bypass causing full database wipe
CVSS 9.4
CVE-2026-8185 MEDIUM
UGREEN CM933 Administrative missing authentication
CVSS 6.3
CVE-2026-42302 CRITICAL
FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox
CVSS 9.8
CVE-2026-42176 MEDIUM
Scoold: Persistent Admin Takeover by Overwriting the admins Configuration Setting via Forged JWT (missing `jti` validation)
CVSS 6.7
CVE-2026-44338 HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
CVE-2026-6736 MEDIUM
GitHub Enterprise Server Signup - External Identity Provider Bypass
CVSS 6.5
CVE-2026-7415 CRITICAL
Open MQTT orchestration without read/write ACLs in Yarbo robot firmware
CVSS 9.8
CVE-2026-8031 MEDIUM
PicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authentication
CVSS 5.3
CVE-2026-41930 CRITICAL
Vvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdmin
CVSS 9.8
CVE-2026-7844 MEDIUM
chatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authentication
CVSS 6.3
CVE-2026-36356 CRITICAL
MeiG Smart FORGE_SLT711 MDM9607.LE.1.0-00110 - Command Injection
CVSS 9.1
CVE-2026-42222 HIGH
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
CVSS 8.1
CVE-2026-42221 HIGH
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
CVSS 8.1
CVE-2026-42796 CRITICAL
Arelle < 2.39.10 Unauthenticated RCE via /rest/configure
CVSS 9.8
CVE-2026-7723 HIGH
PrefectHQ prefect WebSocket Endpoint in missing authentication
CVSS 7.3
CVE-2026-7714 MEDIUM
crocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authentication
CVSS 6.5
CVE-2026-39858 CRITICAL
Traefik: Forwarded alias spoofing top pre-auth decision bypass
CVSS 10.0
CVE-2026-35514 MEDIUM
Unauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions in Chartbrew
CVSS 6.5
CVE-2026-0204 HIGH
SonicWall SonicOS <=6.5.5.1-6n - Auth Bypass
CVSS 8.0
CVE-2026-41940 CRITICAL KEV
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
CVE-2026-3893 CRITICAL
Carlson Software VASCO-B GNSS Receiver Missing Authentication for Critical Function
CVSS 9.4
Details
Vulnerabilities 2,343
Exploit Likelihood High