CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,205 vulnerabilities with CWE-306
CVE-2026-25192 CRITICAL
CTEK Chargeportal Missing Authentication for Critical Function
CVSS 9.4
CVE-2026-22898 CRITICAL
QNAP QVR Pro < 2.7.4.14 - Missing Authentication for Critical Function
CVSS 9.8
CVE-2026-33070 LOW
FileRise has Unauthenticated Share Link Deletion
CVSS 3.7
CVE-2026-4476 MEDIUM
Yi Technology YI Home Camera CGI Endpoint ipc missing authentication
CVSS 6.3
CVE-2026-33038 HIGH
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
CVSS 8.1
CVE-2026-33017 CRITICAL KEV
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
CVE-2026-21992 CRITICAL
Oracle Identity Manager 12.2.1.4.0 - RCE
CVSS 9.8
CVE-2026-32985 CRITICAL
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
CVSS 9.8
CVE-2026-22731 HIGH
Authentication Bypass under Actuator Health groups paths
CVSS 8.2
CVE-2026-32041 MEDIUM
OpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth Bootstrap
CVSS 6.9
CVE-2026-24062 HIGH
Insufficient XPC Client validation leading to local privilege escalation in Arturia Software Center
CVSS 7.8
CVE-2026-2603 HIGH
Keycloak: keycloak: unauthorized authentication via disabled saml identity provider
CVSS 8.1
CVE-2026-22174 MEDIUM
OpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP Probe
CVSS 6.8
CVE-2026-22727 HIGH
Cloud Foundry unprotected internal endpoints
CVSS 7.5
CVE-2026-1264 HIGH
IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls
CVSS 7.1
CVE-2026-3207 CRITICAL
TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability
CVSS 9.8
CVE-2026-32297 HIGH
Angeet ES3 KVM unauthenticated arbitrary file write
CVSS 7.5
CVE-2026-32296 HIGH
Sipeed NanoKVM unauthenticated Wi-Fi configuration endpoint
CVSS 8.2
CVE-2026-32291 MEDIUM
GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console
CVSS 6.8
CVE-2026-4312 CRITICAL
DrangSoft|GCB/FCB Audit Software - Missing Authentication
CVSS 9.8
CVE-2026-4187 MEDIUM
Tiandy Easy7 7.17.0 - Auth Bypass
CVSS 5.3
CVE-2026-3558 HIGH
Philips Hue Bridge - Auth Bypass
CVSS 8.1
CVE-2026-32594 HIGH
Parse Server GraphQL WebSocket endpoint bypasses security middleware
CVSS 7.3
CVE-2026-2491 MEDIUM
Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability
CVSS 6.3
CVE-2026-20995 MEDIUM
Samsung Mobile Smart Switch - Auth Bypass
CVSS 5.3
Details
Vulnerabilities 2,205
Exploit Likelihood High