CWE-306: Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
1,724 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-41940 — WebPros cPanel and WHM Authentication Bypass via Login Flow
- CVE-2026-24423 — SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
- CVE-2025-34077 — WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
- CVE-2025-3248 — Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
- CVE-2024-5910 — Expedition: Missing Authentication Leads to Admin Account Takeover
- CVE-2024-47575 — A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
- CVE-2025-34073 — stamparm/maltrail <=0.54 Remote Command Execution
- CVE-2026-20253 — Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
- CVE-2025-0108 — PAN-OS: Authentication Bypass in the Management Web Interface
- CVE-2026-39987 — marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
- CVE-2025-34111 — Tiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE
- CVE-2026-33017 — Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
- CVE-2025-24865 — mySCADA myPRO Manager Missing Authentication for Critical Function
- CVE-2025-4008 — Arbitrary Command Injection in Smartbedded MeteoBridge
- CVE-2024-12847 — NETGEAR DGN setup.cgi OS Command Injection
- CVE-2025-34103 — WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
- CVE-2024-24578 — RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
- CVE-2025-34100 — BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
- CVE-2025-34116 — IPFire < 2.19 Core Update 101 proxy.cgi RCE
- CVE-2025-34101 — Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
Recently published
- CVE-2026-11838 — Improper Authorization in Yordam Informatics' Library Reservation System
- CVE-2026-85981 — Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-86728 — AVideo through 29.0 Unauthenticated Disclosure via epg.json.php
- CVE-2026-86727 — AVideo through 29.0 Information Disclosure via stats.json.php
- CVE-2026-62645 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web inte
- CVE-2026-19397 — Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby use
- CVE-2026-86543 — knowns before 0.30.0 Unauthenticated Management API Exposure
- CVE-2026-86506 — In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed prof
- CVE-2026-86502 — In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code ex
- CVE-2026-86486 — In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
- CVE-2026-86480 — In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri
- CVE-2026-79645 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78480 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-80132 — ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a
- CVE-2026-76578 — Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci
- CVE-2026-86293 — SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authentication
- CVE-2026-86292 — SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentication
- CVE-2026-16876 — An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentica