CWE-306: Missing Authentication
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Yearly Trend
Top Affected Vendors
All Missing Authentication CVEs (688)
This vulnerability allows authentication bypass on Unitree Go2, G1, H1, and B2 robots by accepting any handshake secret containing the substring 'unit...
Sep 26, 2025This vulnerability allows authenticated high-privileged remote attackers to read arbitrary files from the controller's file system through a web appli...
Jun 16, 2025This vulnerability in the WP Affiliate Disclosure WordPress plugin allows attackers to perform unauthorized actions through Cross-Site Request Forgery...
Dec 21, 2025An unauthenticated file upload vulnerability in Fanvil x210 V2 IP phones allows attackers on the local network to store arbitrary files on the device ...
Dec 5, 2025The Xtooltech Xtool AnyScan Android application version 4.40.40 has a missing authentication vulnerability in its update server endpoint. This allows ...
Nov 24, 2025This vulnerability allows team administrators without member invite privileges to obtain a team's invite ID through the team restore API endpoint. Aff...
Aug 21, 2025This vulnerability in HCL DevOps Deploy/Launch allows authenticated users to access sensitive information about other users due to insufficient author...
Mar 24, 2025In Danswer AI version 0.4.1, unauthenticated attackers can sign up as basic users and create credentials linked to existing connectors, which should b...
Mar 20, 2025This vulnerability in infiniflow/ragflow v0.12.0 allows authenticated users to view other users' invite lists without proper authorization. This expos...
Mar 20, 2025This vulnerability in IBM DevOps Deploy and UrbanCode Deploy allows authenticated users to access sensitive information about other users due to missi...
Feb 8, 2025This vulnerability allows unauthenticated attackers on the same local network as a Starlink Dish to execute administrative actions via gRPC requests b...
Dec 11, 2025This vulnerability allows attackers to spoof user interface elements in Chrome's fullscreen mode by tricking users into performing specific gestures o...
Nov 10, 2025This vulnerability allows attackers to spoof the Chrome Omnibox (address bar) security UI on Android devices through specific user gestures. Attackers...
Nov 10, 2025A missing authentication vulnerability in some Lenovo Tablets allows unauthorized users with physical access to modify Control Center settings when th...
Jan 14, 2026This vulnerability in Mattermost allows authenticated users to access files and subscribe to blocks in Boards they shouldn't have permission to view. ...
Dec 2, 2025This vulnerability allows a local attacker to make unauthorized configuration changes to HCL BigFix IVR without authentication. It affects systems run...
Jan 7, 2026An information disclosure vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to retrieve sensitive administrat...
Feb 6, 2026Avation Light Engine Pro exposes its configuration and control interface without authentication, allowing anyone on the network to access and modify l...
Feb 3, 2026This vulnerability allows remote attackers to access administrative functionality without authentication in Interinfo DreamMaker software. Attackers c...
Jan 30, 2026The Pix-Link LV-WR21Q access point has an authentication bypass vulnerability in its /goform/getHomePageInfo endpoint, allowing unauthenticated attack...
Jan 27, 2026CVE-2025-59097 is an authentication bypass vulnerability in dormakaba exos 9300 Access Manager configuration software. It allows unauthenticated attac...
Jan 26, 2026This vulnerability allows unauthenticated attackers to access the SOAP API on exos 9300 servers, enabling them to create arbitrary access log events a...
Jan 26, 2026This vulnerability allows remote unauthenticated attackers to exploit insecure .NET Remoting in Entrust IFI's SmartCardController service. Attackers c...
Jan 15, 2026This vulnerability allows attackers to execute arbitrary operating system commands with root privileges on Ruckus vRIoT IoT Controller devices. Attack...
Jan 9, 2026OpenFlagr versions up to 1.1.18 contain an authentication bypass vulnerability in HTTP middleware. Attackers can craft requests to bypass authenticati...
Jan 7, 2026This CVE describes an authentication bypass vulnerability in D-Link DSL/DIR/DNS devices that allows unauthenticated attackers to modify DNS settings v...
Jan 5, 2026The WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) has a broken access control vulnerability in the initial configuration wizard.cgi e...
Dec 18, 2025This vulnerability allows unauthenticated attackers to execute administrative commands on WODESYS WD-R608U routers (also known as WDR122B V2.0 and WDR...
Dec 18, 2025This vulnerability in COMMAX Smart Home System allows unauthenticated attackers to retrieve RTSP credentials in plain-text by accessing the /overview....
Dec 9, 2025The COMMAX Smart Home System has an unauthenticated configuration modification vulnerability that allows attackers to change system settings and cause...
Dec 9, 2025This vulnerability allows remote unauthenticated attackers to read arbitrary files, write files, and execute code on Entrust Instant Financial Issuanc...
Dec 9, 2025AirKeyboard iOS App 1.0.5 has a missing authentication vulnerability that allows unauthenticated attackers to remotely inject arbitrary keystrokes int...
Dec 4, 2025This vulnerability allows attackers to bypass multi-factor authentication in PingFederate OTP Integration Kit by exploiting improper HTTP method and s...
Dec 4, 2025The Iskra iHUB and iHUB Lite smart metering gateways expose their web management interfaces without requiring any authentication. This allows unauthen...
Dec 2, 2025SiRcom SMART Alert (SiSA) has an authentication bypass vulnerability that allows unauthenticated attackers to access backend APIs using browser develo...
Nov 25, 2025This CVE describes an authentication bypass vulnerability in TVT Digital's NVMS-9000 firmware used by many DVR/NVR/IP camera products. Unauthenticated...
Nov 24, 2025PLANEX CS-QP50F-ING2 smart cameras expose an unauthenticated HTTP configuration backup interface. Remote attackers can download backup files containin...
Nov 14, 2025Denver SHO-110 IP cameras expose an unauthenticated HTTP endpoint on port 8001 that allows remote attackers to retrieve image snapshots. This backdoor...
Nov 14, 2025About Missing Authentication (CWE-306)
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Our database tracks 688 CVEs classified as CWE-306, with 336 rated critical and 245 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.
External reference: View CWE-306 on MITRE CWE →
Monitor Missing Authentication Vulnerabilities
Get alerted when new Missing Authentication CVEs affect your infrastructure.
Start Monitoring Free