CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

654
Total CVEs
312
Critical
235
High
8.4
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Socomec 10
3 Q Free 10
4 Vasion 9
5 Sap 9
6 Microsoft 9
7 Siemens 9
8 Schneider Electric 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (654)

CVE-2026-23693
10.0

The ElementsKit Lite WordPress plugin versions before 3.7.9 expose an unauthenticated REST endpoint that accepts Mailchimp API credentials. Unauthenti...

Feb 23, 2026
CVE-2026-1633
10.0

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter's web management interface lacks authentication, allowing any unauthenticated user to acce...

Feb 4, 2026
CVE-2025-58083
10.0

The General Industrial Controls Lynx+ Gateway has a critical authentication bypass vulnerability in its embedded web server that allows unauthenticate...

Nov 15, 2025
CVE-2025-55108
10.0

Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read/write, and other unauthorized actions when mutual SSL/TLS ...

Nov 5, 2025
CVE-2025-52665
EPSS 10.6% 10.0

An authentication bypass vulnerability in UniFi Access door control software allows attackers on the management network to access administrative APIs ...

Oct 31, 2025
CVE-2025-9574
10.0

CVE-2025-9574 is a critical missing authentication vulnerability in ABB ALS-mini-s4 IP and ALS-mini-s8 IP devices that allows unauthenticated attacker...

Oct 20, 2025
CVE-2025-41656
10.0

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with high privileges on affected devices. The issue ...

Jul 1, 2025
CVE-2025-32440
10.0

CVE-2025-32440 is an authentication bypass vulnerability in NetAlertX that allows unauthenticated attackers to execute sensitive administrative functi...

May 27, 2025
CVE-2025-36535
10.0

This critical vulnerability in an embedded web server allows unauthenticated remote attackers to access the device without any authentication. This af...

May 21, 2025
CVE-2024-46506
EPSS 82.1% 10.0

CVE-2024-46506 is an unauthenticated remote command injection vulnerability in NetAlertX that allows attackers to execute arbitrary commands on affect...

May 13, 2025
CVE-2025-32433
KEV EPSS 49.9% 10.0

This CVE describes a critical vulnerability in Erlang/OTP's SSH server that allows unauthenticated remote code execution. Attackers can exploit a flaw...

Apr 16, 2025
CVE-2025-24865
EPSS 64.1% 10.0

CVE-2025-24865 allows unauthenticated access to the mySCADA myPRO Manager administrative web interface. Attackers can retrieve sensitive information a...

Feb 13, 2025
CVE-2024-56799
10.0

Simofa versions before 0.2.7 have an authentication bypass vulnerability in the RouteLoader class that exposes API routes that should require authenti...

Dec 30, 2024
CVE-2024-48966
10.0

This critical vulnerability allows attackers with physical access to a service technician's computer to access ventilator diagnostic information and m...

Nov 14, 2024
CVE-2023-49617
10.0

The MachineSense API lacks authentication controls, allowing remote attackers to access and modify sensitive information without credentials. This aff...

Feb 1, 2024
CVE-2022-29226
10.0

This vulnerability in Envoy's OAuth filter allows attackers to bypass authentication by providing any access token, even invalid ones. It affects all ...

Jun 9, 2022
CVE-2020-10640
10.0

This critical vulnerability in Emerson OpenEnterprise allows attackers to execute arbitrary commands with system privileges or perform remote code exe...

Feb 24, 2022
CVE-2021-43832
10.0

CVE-2021-43832 is a critical authentication bypass vulnerability in Spinnaker, an open-source continuous delivery platform. It allows any user with ac...

Jan 4, 2022
CVE-2021-20998
10.0

This critical vulnerability in WAGO managed switches allows unauthenticated attackers to create new user accounts via specially crafted network packet...

May 13, 2021
CVE-2020-26829
10.0

CVE-2020-26829 is a critical authentication bypass vulnerability in SAP NetWeaver AS JAVA's P2P cluster communication. It allows unauthenticated attac...

Dec 9, 2020
CVE-2020-26821
10.0

CVE-2020-26821 is a critical vulnerability in SAP Solution Manager's SVG Converter Service that allows unauthenticated attackers to compromise the sys...

Nov 10, 2020
CVE-2020-26823
10.0

This vulnerability allows unauthenticated attackers to compromise SAP Solution Manager systems due to missing authorization checks in the Upgrade Diag...

Nov 10, 2020
CVE-2025-3498
9.9

An unauthenticated attacker with management network access can exploit exposed REST APIs on Radiflow iSAP Smart Collector devices to access all system...

Jul 9, 2025
CVE-2024-32764
9.9

This vulnerability in myQNAPcloud Link allows attackers to access critical functions without authentication. It affects users running vulnerable versi...

Apr 26, 2024
CVE-2019-11684
9.9

This vulnerability allows unauthenticated attackers to access a limited subset of certificates stored in the Windows operating system through improper...

Feb 26, 2021
CVE-2026-27944
9.8

Nginx UI versions before 2.3.3 expose an unauthenticated API endpoint that discloses encryption keys in response headers, allowing attackers to downlo...

Mar 5, 2026
CVE-2026-27012
9.8

OpenSTAManager versions 2.9.8 and earlier contain an authentication bypass and privilege escalation vulnerability that allows attackers to arbitrarily...

Mar 3, 2026
CVE-2026-2624
9.8

This critical vulnerability allows attackers to bypass authentication mechanisms in ePati Antikor Next Generation Firewall (NGFW), potentially gaining...

Feb 25, 2026
CVE-2025-14577
9.8

Slican NCP/IPL/IPM/IPU devices contain a PHP function injection vulnerability in the /webcti/session_ajax.php endpoint. Unauthenticated remote attacke...

Feb 24, 2026
CVE-2025-30410
9.8

This critical vulnerability allows attackers to access and manipulate sensitive data without authentication in Acronis Cyber Protect products. It affe...

Feb 20, 2026
CVE-2025-8350
9.8

This vulnerability in BiEticaret CMS allows attackers to bypass authentication and manipulate HTTP responses through Execution After Redirect and Miss...

Feb 19, 2026
CVE-2026-1670
9.8

This vulnerability allows unauthenticated attackers to remotely change the password recovery email address via an exposed API endpoint. This affects H...

Feb 17, 2026
CVE-2026-26333
9.8

Calero VeraSMART versions before 2022 R1 expose an unauthenticated .NET Remoting service on port 8001, allowing remote attackers to read/write arbitra...

Feb 13, 2026
CVE-2026-26190
9.8

This critical vulnerability in Milvus vector database allows unauthenticated attackers to bypass authentication and execute arbitrary operations. Atta...

Feb 13, 2026
CVE-2026-1729
9.8

This critical vulnerability in the AdForest WordPress theme allows unauthenticated attackers to bypass authentication and log in as any user, includin...

Feb 12, 2026
CVE-2026-24789
9.8

This vulnerability allows unauthenticated attackers to remotely change device passwords via an unprotected API endpoint. It affects systems running vu...

Feb 11, 2026
CVE-2026-25505
9.8

Bambuddy versions before 0.1.7 have two critical authentication flaws: a hardcoded JWT secret key in source code and missing authentication checks on ...

Feb 4, 2026
CVE-2022-50981
9.8

CVE-2022-50981 allows unauthenticated remote attackers to gain full administrative access to affected devices because they ship without a default pass...

Feb 2, 2026
CVE-2026-1453
9.8

An unauthenticated attacker can create or delete administrator accounts on KiloView Encoder Series devices, granting full administrative control. This...

Jan 29, 2026
CVE-2026-24423
KEV 9.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on SmarterMail servers by pointing them to maliciou...

Jan 23, 2026
CVE-2021-47891
9.8

CVE-2021-47891 is a critical remote code execution vulnerability in Unified Remote 3.9.0.2463 that allows attackers to send crafted network packets to...

Jan 23, 2026
CVE-2026-1364
9.8

CVE-2026-1364 is a critical missing authentication vulnerability in IAQS and I6 systems developed by JNC. Unauthenticated remote attackers can directl...

Jan 23, 2026
CVE-2026-24124
9.8

Dragonfly versions 2.4.1-rc.0 and below have missing authentication and authorization checks on Job API endpoints, allowing unauthenticated users with...

Jan 22, 2026
CVE-2026-23944
9.8

CVE-2026-23944 is an authentication bypass vulnerability in Arcane Docker management interface that allows unauthenticated attackers to proxy requests...

Jan 19, 2026
CVE-2026-23744
EPSS 11.6% 9.8

MCPJam inspector versions 1.4.2 and earlier contain a critical remote code execution vulnerability. Attackers can send a crafted HTTP request that tri...

Jan 16, 2026
CVE-2026-1019
9.8

The Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability that allows unauthenticated remote attackers to re...

Jan 16, 2026
CVE-2025-62582
9.8

Delta Electronics DIAView has a critical authentication bypass vulnerability (CWE-306) that allows attackers to bypass authentication mechanisms and g...

Jan 16, 2026
CVE-2023-54335
9.8

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without valid credentials by manipulating login reques...

Jan 13, 2026
CVE-2026-21446
9.8

Bagisto eCommerce platform versions before 2.3.10 have unprotected API endpoints that remain accessible after installation. Unauthenticated attackers ...

Jan 2, 2026
CVE-2025-65856
9.8

CVE-2025-65856 is an authentication bypass vulnerability in Xiongmai XM530 IP cameras that allows unauthenticated remote attackers to access sensitive...

Dec 22, 2025

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 654 CVEs classified as CWE-306, with 312 rated critical and 235 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free