CWE-306: Missing Authentication
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Yearly Trend
Top Affected Vendors
All Missing Authentication CVEs (654)
The ElementsKit Lite WordPress plugin versions before 3.7.9 expose an unauthenticated REST endpoint that accepts Mailchimp API credentials. Unauthenti...
Feb 23, 2026The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter's web management interface lacks authentication, allowing any unauthenticated user to acce...
Feb 4, 2026The General Industrial Controls Lynx+ Gateway has a critical authentication bypass vulnerability in its embedded web server that allows unauthenticate...
Nov 15, 2025Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read/write, and other unauthorized actions when mutual SSL/TLS ...
Nov 5, 2025An authentication bypass vulnerability in UniFi Access door control software allows attackers on the management network to access administrative APIs ...
Oct 31, 2025CVE-2025-9574 is a critical missing authentication vulnerability in ABB ALS-mini-s4 IP and ALS-mini-s8 IP devices that allows unauthenticated attacker...
Oct 20, 2025This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with high privileges on affected devices. The issue ...
Jul 1, 2025CVE-2025-32440 is an authentication bypass vulnerability in NetAlertX that allows unauthenticated attackers to execute sensitive administrative functi...
May 27, 2025This critical vulnerability in an embedded web server allows unauthenticated remote attackers to access the device without any authentication. This af...
May 21, 2025CVE-2024-46506 is an unauthenticated remote command injection vulnerability in NetAlertX that allows attackers to execute arbitrary commands on affect...
May 13, 2025This CVE describes a critical vulnerability in Erlang/OTP's SSH server that allows unauthenticated remote code execution. Attackers can exploit a flaw...
Apr 16, 2025CVE-2025-24865 allows unauthenticated access to the mySCADA myPRO Manager administrative web interface. Attackers can retrieve sensitive information a...
Feb 13, 2025Simofa versions before 0.2.7 have an authentication bypass vulnerability in the RouteLoader class that exposes API routes that should require authenti...
Dec 30, 2024This critical vulnerability allows attackers with physical access to a service technician's computer to access ventilator diagnostic information and m...
Nov 14, 2024The MachineSense API lacks authentication controls, allowing remote attackers to access and modify sensitive information without credentials. This aff...
Feb 1, 2024This vulnerability in Envoy's OAuth filter allows attackers to bypass authentication by providing any access token, even invalid ones. It affects all ...
Jun 9, 2022This critical vulnerability in Emerson OpenEnterprise allows attackers to execute arbitrary commands with system privileges or perform remote code exe...
Feb 24, 2022CVE-2021-43832 is a critical authentication bypass vulnerability in Spinnaker, an open-source continuous delivery platform. It allows any user with ac...
Jan 4, 2022This critical vulnerability in WAGO managed switches allows unauthenticated attackers to create new user accounts via specially crafted network packet...
May 13, 2021CVE-2020-26829 is a critical authentication bypass vulnerability in SAP NetWeaver AS JAVA's P2P cluster communication. It allows unauthenticated attac...
Dec 9, 2020CVE-2020-26821 is a critical vulnerability in SAP Solution Manager's SVG Converter Service that allows unauthenticated attackers to compromise the sys...
Nov 10, 2020This vulnerability allows unauthenticated attackers to compromise SAP Solution Manager systems due to missing authorization checks in the Upgrade Diag...
Nov 10, 2020An unauthenticated attacker with management network access can exploit exposed REST APIs on Radiflow iSAP Smart Collector devices to access all system...
Jul 9, 2025This vulnerability in myQNAPcloud Link allows attackers to access critical functions without authentication. It affects users running vulnerable versi...
Apr 26, 2024This vulnerability allows unauthenticated attackers to access a limited subset of certificates stored in the Windows operating system through improper...
Feb 26, 2021Nginx UI versions before 2.3.3 expose an unauthenticated API endpoint that discloses encryption keys in response headers, allowing attackers to downlo...
Mar 5, 2026OpenSTAManager versions 2.9.8 and earlier contain an authentication bypass and privilege escalation vulnerability that allows attackers to arbitrarily...
Mar 3, 2026This critical vulnerability allows attackers to bypass authentication mechanisms in ePati Antikor Next Generation Firewall (NGFW), potentially gaining...
Feb 25, 2026Slican NCP/IPL/IPM/IPU devices contain a PHP function injection vulnerability in the /webcti/session_ajax.php endpoint. Unauthenticated remote attacke...
Feb 24, 2026This critical vulnerability allows attackers to access and manipulate sensitive data without authentication in Acronis Cyber Protect products. It affe...
Feb 20, 2026This vulnerability in BiEticaret CMS allows attackers to bypass authentication and manipulate HTTP responses through Execution After Redirect and Miss...
Feb 19, 2026This vulnerability allows unauthenticated attackers to remotely change the password recovery email address via an exposed API endpoint. This affects H...
Feb 17, 2026Calero VeraSMART versions before 2022 R1 expose an unauthenticated .NET Remoting service on port 8001, allowing remote attackers to read/write arbitra...
Feb 13, 2026This critical vulnerability in Milvus vector database allows unauthenticated attackers to bypass authentication and execute arbitrary operations. Atta...
Feb 13, 2026This critical vulnerability in the AdForest WordPress theme allows unauthenticated attackers to bypass authentication and log in as any user, includin...
Feb 12, 2026This vulnerability allows unauthenticated attackers to remotely change device passwords via an unprotected API endpoint. It affects systems running vu...
Feb 11, 2026Bambuddy versions before 0.1.7 have two critical authentication flaws: a hardcoded JWT secret key in source code and missing authentication checks on ...
Feb 4, 2026CVE-2022-50981 allows unauthenticated remote attackers to gain full administrative access to affected devices because they ship without a default pass...
Feb 2, 2026An unauthenticated attacker can create or delete administrator accounts on KiloView Encoder Series devices, granting full administrative control. This...
Jan 29, 2026This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on SmarterMail servers by pointing them to maliciou...
Jan 23, 2026CVE-2021-47891 is a critical remote code execution vulnerability in Unified Remote 3.9.0.2463 that allows attackers to send crafted network packets to...
Jan 23, 2026CVE-2026-1364 is a critical missing authentication vulnerability in IAQS and I6 systems developed by JNC. Unauthenticated remote attackers can directl...
Jan 23, 2026Dragonfly versions 2.4.1-rc.0 and below have missing authentication and authorization checks on Job API endpoints, allowing unauthenticated users with...
Jan 22, 2026CVE-2026-23944 is an authentication bypass vulnerability in Arcane Docker management interface that allows unauthenticated attackers to proxy requests...
Jan 19, 2026MCPJam inspector versions 1.4.2 and earlier contain a critical remote code execution vulnerability. Attackers can send a crafted HTTP request that tri...
Jan 16, 2026The Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability that allows unauthenticated remote attackers to re...
Jan 16, 2026Delta Electronics DIAView has a critical authentication bypass vulnerability (CWE-306) that allows attackers to bypass authentication mechanisms and g...
Jan 16, 2026eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without valid credentials by manipulating login reques...
Jan 13, 2026Bagisto eCommerce platform versions before 2.3.10 have unprotected API endpoints that remain accessible after installation. Unauthenticated attackers ...
Jan 2, 2026CVE-2025-65856 is an authentication bypass vulnerability in Xiongmai XM530 IP cameras that allows unauthenticated remote attackers to access sensitive...
Dec 22, 2025About Missing Authentication (CWE-306)
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Our database tracks 654 CVEs classified as CWE-306, with 312 rated critical and 235 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.
External reference: View CWE-306 on MITRE CWE →
Monitor Missing Authentication Vulnerabilities
Get alerted when new Missing Authentication CVEs affect your infrastructure.
Start Monitoring Free