CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

684
Total CVEs
333
Critical
244
High
8.5
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Sap 12
3 Siemens 11
4 Socomec 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Vasion 9
9 Apache 8
10 Dlink 8

All Missing Authentication CVEs (684)

CVE-2021-31793
7.5

This vulnerability allows unauthenticated attackers to access live snapshots and video streams from NightOwl WDB-20-V2 doorbell cameras. The device's ...

May 6, 2021
CVE-2020-35755
7.5

CVE-2020-35755 is an information disclosure vulnerability in Libre Wireless LS9 devices where the luci_service daemon on port 7777 allows unauthentica...

May 3, 2021
CVE-2021-20990
7.5

Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older expose an internal management service on port 8000 without authentication....

Apr 19, 2021
CVE-2021-28148
7.5

This vulnerability allows unauthenticated attackers to send unlimited requests to a specific Grafana Enterprise API endpoint, causing denial of servic...

Mar 22, 2021
CVE-2020-19419
7.5

This vulnerability allows remote attackers to access sensitive device information from the Emerson Smart Wireless Gateway 1420 administrator console w...

Mar 10, 2021
CVE-2019-25020
7.5

This vulnerability allows unauthenticated attackers to retrieve administrative configuration data from Scytl sVote 2.1 systems by sending POST request...

Feb 27, 2021
CVE-2020-28946
7.5

An improper webserver configuration in Plum IK-401 devices allows unauthenticated attackers with network access to retrieve the device configuration f...

Dec 8, 2020
CVE-2020-28937
7.5

CVE-2020-28937 is a missing authentication vulnerability in OpenClinic that allows unauthenticated attackers to access any patient's medical test resu...

Dec 3, 2020
CVE-2025-11198
7.4

An unauthenticated attacker can replace legitimate vSRX images with malicious ones in Juniper Security Director Policy Enforcer. This allows network-b...

Oct 9, 2025
CVE-2021-21535
7.4

CVE-2021-21535 is a missing authentication vulnerability in Dell Hybrid Client that allows local unauthenticated attackers to gain root access. This a...

Apr 30, 2021
CVE-2025-3646
7.3

This authorization bypass vulnerability in Petlibro Smart Pet Feeder Platform allows unauthorized users to add themselves as shared owners to any devi...

Jan 4, 2026
CVE-2024-45356
7.3

This vulnerability allows attackers to bypass authorization controls in Xiaomi phone frameworks, enabling unauthorized access to sensitive system meth...

Mar 27, 2025
CVE-2023-40585
7.3

This vulnerability exposes the Ironic API without authentication when TLS is disabled and API/Conductor services aren't separated. It affects MetalΒ³ ...

Aug 25, 2023
CVE-2026-20803
7.2

This vulnerability in SQL Server allows attackers with existing network access to bypass authentication checks and execute privileged functions. It af...

Jan 13, 2026
CVE-2025-20085
7.2

An unauthenticated denial-of-service vulnerability in Socomec DIRIS Digiware M-70's Modbus RTU over TCP functionality allows attackers to crash the de...

Dec 1, 2025
CVE-2024-49572
7.2

An unauthenticated denial-of-service vulnerability in Socomec DIRIS Digiware M-70's Modbus TCP functionality allows attackers to send specially crafte...

Dec 1, 2025
CVE-2025-54478
7.2

The Mattermost Confluence Plugin before version 1.5.0 has an authentication bypass vulnerability that allows unauthenticated attackers to edit channel...

Aug 11, 2025
CVE-2025-44004
7.2

The Mattermost Confluence Plugin before version 1.5.0 has an authorization bypass vulnerability that allows attackers to create unauthorized channel s...

Aug 11, 2025
CVE-2024-31525
7.2

CVE-2024-31525 is a privilege escalation vulnerability in Peppermint Ticket Management 0.4.6 where regular users can become administrators due to clie...

Mar 5, 2025
CVE-2024-47902
7.2

This vulnerability allows unauthenticated attackers to execute operating system commands via unauthenticated GET requests to the web server in affecte...

Oct 23, 2024
CVE-2021-44255
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on MotionEye and MotionEyeOS servers by uploading malicious Python pickle ...

Jan 31, 2022
CVE-2025-66445
7.1

An authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer allows attackers to access restricte...

Dec 24, 2025
CVE-2025-48397
7.1

This vulnerability allows privileged users to log in without proper credentials after enabling an application protocol in Eaton BLSS. It affects syste...

Nov 3, 2025
CVE-2021-37696
7.1

This vulnerability in tmerc-cogs for Red Discord bot allows any user to access sensitive information by crafting a specific MassDM message. It affects...

Aug 11, 2021
CVE-2020-35226
7.1

CVE-2020-35226 allows unauthenticated attackers to modify DHCP configuration on affected NETGEAR switches. This vulnerability enables unauthorized net...

Mar 10, 2021
CVE-2025-14038
7.0

EDB Hybrid Manager contains an authentication bypass vulnerability in gRPC endpoints due to Istio Gateway misconfiguration. Unauthenticated attackers ...

Dec 15, 2025
CVE-2020-25697
7.0

This CVE describes a privilege escalation vulnerability in Xorg X11 server where clients can connect without proper authentication. Attackers can impe...

May 26, 2021
CVE-2025-32063
6.8

A misconfiguration vulnerability in Bosch Infotainment ECUs during systemd service startup enables developer features including disabled firewall and ...

Feb 15, 2026
CVE-2025-64770
6.8

This vulnerability allows unauthenticated attackers to access ONVIF services on affected camera systems, exposing sensitive configuration information....

Nov 20, 2025
CVE-2025-62674
6.8

This vulnerability allows unauthenticated attackers to access RTSP services on affected camera systems, potentially exposing sensitive configuration i...

Nov 20, 2025
CVE-2025-60856
6.8

The Reolink Video Doorbell WiFi DB_566128M5MP_W has an unsecured UART/serial console that allows physical attackers to gain root shell access and exec...

Oct 20, 2025
CVE-2025-25736
6.8

This vulnerability allows unauthenticated attackers to gain root shell access to Kapsch TrafficCom RIS-9260 RSU devices via Android Debug Bridge (ADB)...

Aug 26, 2025
CVE-2025-32876
6.8

This vulnerability allows attackers within Bluetooth range to eavesdrop on communications between COROS PACE 3 smartwatches and paired devices. The BL...

Jun 20, 2025
CVE-2024-5143
6.8

This vulnerability allows device administrators to change SMTP server settings without re-entering credentials, potentially exposing original SMTP cre...

May 23, 2024
CVE-2024-35143
6.7

IBM Planning Analytics Local 2.0 and 2.1 connects to MongoDB without requiring authentication, allowing remote attackers to access the database. This ...

Aug 4, 2024
CVE-2025-42875
6.6

This vulnerability in SAP Internet Communication Framework allows attackers to bypass authentication by reusing valid authorization tokens without pro...

Dec 9, 2025
CVE-2024-45229
6.6

This vulnerability in Versa Director allows unauthenticated attackers to steal authentication tokens from currently logged-in users by exploiting an u...

Sep 20, 2024
CVE-2026-29606
6.5

OpenClaw versions before 2026.2.14 have a webhook signature verification bypass in the voice-call extension when tunnel.allowNgrokFreeTierLoopbackBypa...

Mar 5, 2026
CVE-2022-50980
6.5

An unauthenticated attacker on the same Controller Area Network (CAN) bus can disrupt operations by rapidly switching between configuration presets. T...

Feb 2, 2026
CVE-2022-50979
6.5

This vulnerability allows an unauthenticated attacker on the same network segment to disrupt operations by switching between multiple configuration pr...

Feb 2, 2026
CVE-2025-65828
6.5

An unauthenticated attacker within Bluetooth range can send BLE commands to Meatmeet devices, causing denial of service by shutting down, restarting, ...

Dec 10, 2025
CVE-2025-12969
6.5

This vulnerability allows remote attackers to bypass authentication in Fluent Bit's in_forward input plugin under certain configurations, enabling the...

Nov 24, 2025
CVE-2025-55070
6.5

Mattermost versions before 11 fail to enforce multi-factor authentication on WebSocket connections, allowing unauthenticated users to bypass MFA and a...

Nov 14, 2025
CVE-2025-40817
6.5

This vulnerability affects Siemens LOGO! programmable logic controllers (PLCs) and their SIPLUS variants. An unauthenticated remote attacker can chang...

Nov 11, 2025
CVE-2025-32896
6.5

Unauthorized attackers can exploit Apache SeaTunnel's REST API to read arbitrary files and perform deserialization attacks by submitting malicious job...

Jun 19, 2025
CVE-2025-27803
6.5

This CVE describes a critical authentication bypass vulnerability in certain devices where both the web interface and MQTT server lack any authenticat...

May 21, 2025
CVE-2025-3474
6.5

This CVE describes a missing authentication vulnerability in Drupal Panels that allows attackers to bypass access controls on critical functions. Atta...

Apr 9, 2025
CVE-2023-41186
6.5

This vulnerability allows network-adjacent attackers to access D-Link DAP-1325 router functionality without authentication via the CGI interface. Atta...

May 3, 2024
CVE-2023-27357
6.5

This vulnerability allows network-adjacent attackers to access sensitive information from NETGEAR RAX30 routers without authentication. The flaw exist...

May 3, 2024
CVE-2022-48291
6.5

This CVE describes an authentication bypass vulnerability in the Bluetooth pairing process of Huawei devices. Attackers within Bluetooth range can pot...

Mar 27, 2023

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 684 CVEs classified as CWE-306, with 333 rated critical and 244 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free