CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

667
Total CVEs
319
Critical
241
High
8.4
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Socomec 10
3 Sap 10
4 Q Free 10
5 Schneider Electric 9
6 Vasion 9
7 Microsoft 9
8 Siemens 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (667)

CVE-2021-33543
9.8

Multiple IP camera devices from UDP Technology, Geutebrück, and other vendors allow unauthenticated remote attackers to access sensitive files due to...

Sep 13, 2021
CVE-2021-28913
9.8

CVE-2021-28913 allows unauthenticated attackers to retrieve a hard-coded unique string from BAB TECHNOLOGIE GmbH eibPort V3 devices via the /webif/Sec...

Sep 9, 2021
CVE-2021-37415
9.8

CVE-2021-37415 is an authentication bypass vulnerability in Zoho ManageEngine ServiceDesk Plus where certain REST-API URLs don't require authenticatio...

Sep 1, 2021
CVE-2021-37843
9.8

CVE-2021-37843 is an authentication bypass vulnerability in resolution SAML SSO apps for Atlassian products that allows remote attackers to log into u...

Aug 2, 2021
CVE-2021-22772
9.8

This vulnerability allows attackers to bypass authentication on Schneider Electric Easergy T200 devices, enabling unauthorized control of critical pow...

Jul 21, 2021
CVE-2021-36124
9.8

CVE-2021-36124 is an authentication bypass vulnerability in Echo ShareCare 8.15.5 that allows unauthenticated attackers to access sensitive resources ...

Jul 13, 2021
CVE-2021-33221
9.8

CVE-2021-33221 exposes unauthenticated API endpoints in CommScope Ruckus IoT Controller versions 1.7.1.0 and earlier, allowing attackers to bypass aut...

Jul 7, 2021
CVE-2021-31337
9.8

This vulnerability allows remote attackers to gain unauthorized access to SIMATIC HMI Comfort Panels and SINAMICS Medium Voltage Products via unauthen...

Jun 28, 2021
CVE-2021-30190
9.8

CVE-2021-30190 is an improper access control vulnerability in CODESYS V2 Web-Server that allows unauthenticated attackers to bypass authentication and...

May 25, 2021
CVE-2021-29203
9.8

CVE-2021-29203 is a critical authentication bypass vulnerability in HPE Edgeline Infrastructure Manager that allows remote attackers to execute arbitr...

May 6, 2021
CVE-2020-35757
9.8

This vulnerability allows unauthenticated attackers to enable ADB over TCP on Libre Wireless LS9 devices, granting them root access. Any LS9 device wi...

May 3, 2021
CVE-2021-20697
9.8

CVE-2021-20697 is an authentication bypass vulnerability in D-Link DAP-1880AC access points. It allows remote attackers to gain administrative access ...

Apr 26, 2021
CVE-2020-25218
9.8

CVE-2020-25218 allows attackers to bypass authentication on Grandstream GRP261x VoIP phones' administrative web interface, granting full administrativ...

Mar 29, 2021
CVE-2021-27215
9.8

This vulnerability allows authentication bypass in genua genugate firewall appliances. Attackers can log into admin panels as any user, including root...

Mar 3, 2021
CVE-2021-1396
9.8

Multiple vulnerabilities in Cisco Application Services Engine allow unauthenticated remote attackers to gain privileged access to host-level operation...

Feb 24, 2021
CVE-2021-22652
9.8

CVE-2021-22652 is an unauthenticated remote code execution vulnerability in Advantech iView industrial monitoring software. Attackers can access confi...

Feb 11, 2021
CVE-2020-15798
9.8

This vulnerability allows remote attackers to gain full administrative access to affected Siemens industrial control devices without authentication wh...

Feb 9, 2021
CVE-2020-14245
9.8

CVE-2020-14245 is an authentication bypass vulnerability in HCL OneTest UI that allows unauthenticated attackers to access functionality requiring use...

Feb 4, 2021
CVE-2020-29165
9.8

CVE-2020-29165 is an incorrect access control vulnerability in PacsOne Server that allows remote attackers to gain administrator privileges. This affe...

Feb 3, 2021
CVE-2020-23448
9.8

CVE-2020-23448 is an authentication bypass vulnerability in newbee-mall e-commerce platform that allows remote attackers to gain administrative privil...

Jan 26, 2021
CVE-2020-4958
9.8

CVE-2020-4958 is an authentication bypass vulnerability in IBM Security Identity Governance and Intelligence that allows unauthenticated attackers to ...

Jan 21, 2021
CVE-2020-35190
9.8

This vulnerability allows remote attackers to gain root access to systems running affected Plone Docker images by using a blank password for the root ...

Dec 17, 2020
CVE-2020-35192
9.8

This vulnerability allows remote attackers to gain root access to systems running affected Vault Docker images by using a blank password. It affects a...

Dec 17, 2020
CVE-2020-35195
9.8

This vulnerability allows remote attackers to gain root access to systems running affected HAProxy Docker images by using a blank password. It affects...

Dec 17, 2020
CVE-2020-35197
9.8

This vulnerability allows remote attackers to gain root access to systems running affected memcached Docker images by using a blank password. It affec...

Dec 17, 2020
CVE-2020-35184
9.8

This vulnerability allows remote attackers to gain root access to systems running affected Composer Docker images by using a blank password. Anyone us...

Dec 17, 2020
CVE-2020-35185
9.8

CVE-2020-35185 allows remote attackers to gain root access to systems running vulnerable Ghost Docker images by using a blank password. This affects d...

Dec 17, 2020
CVE-2020-35189
9.8

This vulnerability allows remote attackers to gain root access to Kong Docker containers by using a blank password for the root user. Systems running ...

Dec 17, 2020
CVE-2020-28929
9.8

CVE-2020-28929 allows unauthenticated attackers to remotely download server logs containing administrative hashed credentials via a specific URI in EP...

Dec 16, 2020
CVE-2020-35193
9.8

This vulnerability affects SonarQube Docker images based on Alpine Linux that have a blank root password. Attackers can gain root access to containers...

Dec 16, 2020
CVE-2020-35469
9.8

The Software AG Terracotta Server OSS Docker image version 5.4.1 has a blank root password, allowing remote attackers to gain root access without auth...

Dec 16, 2020
CVE-2020-35464
9.8

CVE-2020-35464 is a critical authentication bypass vulnerability in Weave Cloud Agent Docker image version 1.3.0 where the root user has a blank passw...

Dec 15, 2020
CVE-2020-35466
9.8

The Blackfire Docker image through December 14, 2020 contains a blank root password, allowing remote attackers to gain root access without authenticat...

Dec 15, 2020
CVE-2020-35462
9.8

CVE-2020-35462 allows remote attackers to gain root access to systems running CoScale agent Docker image version 3.16.0 by using a blank password for ...

Dec 15, 2020
CVE-2020-7540
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on Schneider Electric Modicon PLCs via specially crafted HTTP reques...

Dec 11, 2020
CVE-2020-29389
9.8

This vulnerability allows attackers to gain root access to Crux Linux Docker containers by using a blank password for the root account. Systems using ...

Dec 2, 2020
CVE-2020-29058
9.8

This vulnerability allows attackers to retrieve cleartext web-server credentials by making specific CGI requests to affected CDATA optical line termin...

Nov 24, 2020
CVE-2020-3531
9.8

CVE-2020-3531 allows unauthenticated remote attackers to access the back-end database of Cisco IoT Field Network Director (FND) due to improper REST A...

Nov 18, 2020
CVE-2020-13927
9.8

CVE-2020-13927 is a critical authentication bypass vulnerability in Apache Airflow's Experimental API that allows unauthenticated remote attackers to ...

Nov 10, 2020
CVE-2020-12500
9.8

This CVE allows unauthenticated attackers to gain administrative control over affected Pepperl+Fuchs industrial network devices. Attackers can bypass ...

Oct 15, 2020
CVE-2020-24217
9.8

This vulnerability allows unauthenticated attackers to upload malicious firmware to HiSilicon-based video encoders, potentially leading to remote code...

Oct 6, 2020
CVE-2020-6875
9.8

This vulnerability in ZTE networking products allows attackers to bypass authentication through brute-force attacks due to missing access control mech...

Oct 5, 2020
CVE-2020-15851
9.8

CVE-2020-15851 is a critical access control vulnerability in Nakivo Backup & Replication Transporter that allows remote attackers to access unencrypte...

Sep 24, 2020
CVE-2020-11856
9.8

CVE-2020-11856 is a critical remote code execution vulnerability in Micro Focus Operation Bridge Reporter versions 10.40 and earlier. Attackers can ex...

Sep 22, 2020
CVE-2020-23512
9.8

The VR CAM P1 Model P1 v1 has an incorrect access control vulnerability that allows unauthenticated remote attackers to gain complete administrative c...

Sep 15, 2020
CVE-2025-48469
9.6

This vulnerability allows unauthenticated attackers to upload malicious firmware through a public update page. This could lead to backdoor installatio...

Jun 24, 2025
CVE-2024-40087
9.6

Vilo 5 Mesh WiFi System versions up to 5.16.1.33 have an insecure custom TCP service on port 5432 that lacks authentication. Remote attackers can expl...

Oct 21, 2024
CVE-2024-9164
9.6

This vulnerability in GitLab EE allows attackers to run CI/CD pipelines on arbitrary branches, bypassing branch protection rules. It affects GitLab EE...

Oct 11, 2024
CVE-2024-22212
9.6

CVE-2024-22212 is an authentication bypass vulnerability in Nextcloud Global Site Selector that allows attackers to authenticate as any user due to a ...

Jan 18, 2024
CVE-2021-36779
9.6

This vulnerability allows any workload in a Kubernetes cluster running vulnerable SUSE Longhorn versions to execute arbitrary binaries from container ...

Dec 17, 2021

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 667 CVEs classified as CWE-306, with 319 rated critical and 241 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free