CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,343 vulnerabilities with CWE-306
CVE-2026-4810 CRITICAL
Remote Code Execution in Google Agent Development Kit (ADK)
CVE-2026-6129 HIGH
zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication
CVSS 7.3
CVE-2026-6126 HIGH
zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication
CVSS 7.3
CVE-2026-5724 MEDIUM
Missing Authentication on Streaming gRPC Replication Endpoint
CVE-2026-40184 LOW
Unauthenticated Access to Uploaded Files in TREK
CVSS 3.7
CVE-2026-5777 HIGH
Security Misconfiguration Vulnerability in Atom 3x Projector
CVE-2026-39848 MEDIUM
Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
CVSS 6.5
CVE-2026-33788 HIGH
Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs
CVSS 7.8
CVE-2026-4436 HIGH
GPL Odorizers GPL750 Missing Authentication for Critical Function
CVSS 8.6
CVE-2026-39987 CRITICAL KEV
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
CVE-2026-39393 HIGH
Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms
CVSS 8.1
CVE-2026-5300 MEDIUM
Missing Authentication for Critical Function in coolercontrold
CVSS 5.9
CVE-2026-39363 HIGH
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
CVSS 7.5
CVE-2026-35584 MEDIUM
FreeScout <1.8.212 Open Tracking Endpoint - Insecure Direct Object Reference
CVSS 6.5
CVE-2026-35523 HIGH
Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocol
CVSS 7.5
CVE-2026-22679 CRITICAL
Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
CVSS 9.8
CVE-2026-1900 MEDIUM
Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update
CVSS 6.5
CVE-2026-35450 MEDIUM
WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php
CVSS 5.3
CVE-2026-5676 HIGH
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
CVSS 7.3
CVE-2026-26027 HIGH
GLPI 11.0.0-11.0.5 Inventory - Unauthenticated Stored Cross-Site Scripting
CVSS 7.5
CVE-2026-5632 HIGH
assafelovic gpt-researcher HTTP REST API Endpoint missing authentication
CVSS 7.3
CVE-2026-5616 HIGH
JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication
CVSS 7.3
CVE-2026-4272 HIGH
Honeywell Barcode Scanners - Auth Bypass
CVSS 8.1
CVE-2026-34952 CRITICAL
PraisonAI: Missing Authentication in WebSocket Gateway
CVSS 9.1
CVE-2026-32646 HIGH
Gardyn Cloud API Missing Authentication for Critical Function
CVSS 7.5
Details
Vulnerabilities 2,343
Exploit Likelihood High