CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

674
Total CVEs
324
Critical
243
High
8.4
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Sap 11
3 Socomec 10
4 Siemens 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Vasion 9
9 Dlink 8
10 Mattermost 7

All Missing Authentication CVEs (674)

CVE-2024-40087
9.6

Vilo 5 Mesh WiFi System versions up to 5.16.1.33 have an insecure custom TCP service on port 5432 that lacks authentication. Remote attackers can expl...

Oct 21, 2024
CVE-2024-9164
9.6

This vulnerability in GitLab EE allows attackers to run CI/CD pipelines on arbitrary branches, bypassing branch protection rules. It affects GitLab EE...

Oct 11, 2024
CVE-2024-22212
9.6

CVE-2024-22212 is an authentication bypass vulnerability in Nextcloud Global Site Selector that allows attackers to authenticate as any user due to a ...

Jan 18, 2024
CVE-2021-36779
9.6

This vulnerability allows any workload in a Kubernetes cluster running vulnerable SUSE Longhorn versions to execute arbitrary binaries from container ...

Dec 17, 2021
CVE-2021-3825
9.6

CVE-2021-3825 is a critical configuration exposure vulnerability in LiderAhenk's Lider module that allows attackers to retrieve LDAP credentials via a...

Oct 1, 2021
CVE-2026-26288
9.4

This vulnerability allows unauthenticated attackers to impersonate legitimate charging stations by connecting to WebSocket endpoints without proper au...

Mar 6, 2026
CVE-2026-26051
9.4

This CVE describes a critical authentication bypass vulnerability in WebSocket endpoints used for OCPP (Open Charge Point Protocol) communication. Att...

Mar 6, 2026
CVE-2026-22552
9.4

This vulnerability allows unauthenticated attackers to impersonate legitimate charging stations by connecting to WebSocket endpoints without proper au...

Mar 6, 2026
CVE-2025-52024
9.4

The Aptsys POS Platform Web Services module exposes internal API testing tools to unauthenticated users, allowing attackers to discover and execute cr...

Jan 23, 2026
CVE-2025-54816
9.4

This vulnerability allows unauthenticated attackers to establish WebSocket connections to affected systems, bypassing authentication entirely. Attacke...

Jan 22, 2026
CVE-2025-13607
9.4

This vulnerability allows unauthenticated attackers to access camera configuration information, including account credentials, by exploiting a specifi...

Dec 10, 2025
CVE-2025-65112
9.4

PubNet versions before 1.1.3 allow unauthenticated attackers to upload packages as any user by manipulating the author-id parameter in the /api/storag...

Nov 29, 2025
CVE-2025-20358
9.4

This vulnerability allows unauthenticated remote attackers to bypass authentication in Cisco Unified CCX's Contact Center Express Editor, gaining admi...

Nov 5, 2025
CVE-2025-30135
9.4

IROAD Dashcam FX2 devices lack authentication on HTTP and RTSP interfaces, allowing attackers to download stored video recordings and view live footag...

Jul 25, 2025
CVE-2024-12106
9.4

This vulnerability allows unauthenticated attackers to configure LDAP settings in WhatsUp Gold, potentially enabling them to redirect authentication t...

Dec 31, 2024
CVE-2024-10205
9.4

This authentication bypass vulnerability in Hitachi Ops Center Analyzer and Hitachi Infrastructure Analytics Advisor allows attackers to bypass authen...

Dec 17, 2024
CVE-2024-9137
9.4

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected Moxa devices due to missing authentication checks in the...

Oct 14, 2024
CVE-2022-43761
9.4

CVE-2022-43761 is a critical authentication bypass vulnerability in B&R APROL industrial automation systems. It allows unauthenticated attackers to re...

Feb 8, 2023
CVE-2022-26833
9.4

CVE-2022-26833 is an improper authentication vulnerability in Open Automation Software OAS Platform that allows unauthenticated attackers to access th...

May 25, 2022
CVE-2020-25747
9.4

This vulnerability allows remote attackers to bypass authentication on Rubetek security cameras' Telnet service, gaining unauthorized access to RTSP a...

Sep 25, 2020
CVE-2025-70146
9.1

This vulnerability allows remote attackers to perform administrative operations without authentication in ProjectWorlds Online Time Table Generator 1....

Feb 18, 2026
CVE-2026-25848
9.1

This authentication bypass vulnerability in JetBrains Hub allows attackers to perform administrative actions without proper credentials. All organizat...

Feb 9, 2026
CVE-2026-2234
9.1

CVE-2026-2234 is a missing authentication vulnerability in HGiga's C&Cm@il software that allows unauthenticated remote attackers to read and modify an...

Feb 9, 2026
CVE-2026-1632
9.1

MOMA Seismic Station versions v2.4.2520 and earlier expose their web management interface without requiring authentication. This allows unauthenticate...

Feb 3, 2026
CVE-2026-25137
9.1

The NixOS Odoo package exposes the database manager without authentication, allowing unauthorized actors to delete or download the entire database and...

Feb 2, 2026
CVE-2026-21445
9.1

CVE-2026-21445 is a critical authentication bypass vulnerability in Langflow that allows unauthenticated attackers to access sensitive user conversati...

Jan 2, 2026
CVE-2025-34434
9.1

AVideo versions before 20.1 with the ImageGallery plugin enabled are vulnerable to unauthenticated file upload and deletion. Attackers can upload mali...

Dec 17, 2025
CVE-2025-59345
9.1

Dragonfly Manager web UI endpoints /api/v1/jobs and /preheats lack authentication in versions before 2.1.0, allowing unauthenticated attackers to crea...

Sep 17, 2025
CVE-2025-43983
9.1

KuWFi CPF908-CP5 devices running WEB5.0_LCD_20210125 firmware have unauthenticated API endpoints that allow attackers to access sensitive information,...

Aug 14, 2025
CVE-2025-3461
9.1

Quantenna Wi-Fi chips have an unauthenticated telnet interface enabled by default, allowing attackers to remotely access and control affected devices ...

Jun 8, 2025
CVE-2025-40664
9.1

CVE-2025-40664 is a missing authentication vulnerability in TCMAN GIM v11 that allows unauthenticated attackers to access user management endpoints. T...

May 26, 2025
CVE-2025-4557
9.1

The ZONG YU Parking Management System has missing authentication on specific APIs, allowing unauthenticated remote attackers to operate critical syste...

May 12, 2025
CVE-2024-23943
9.1

An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized access to the cloud API on affected devices due to missing auth...

Mar 18, 2025
CVE-2025-0108
KEV EPSS 94% 9.1

An authentication bypass vulnerability in Palo Alto Networks PAN-OS software allows unauthenticated attackers with network access to the management we...

Feb 12, 2025
CVE-2025-26361
9.1

CVE-2025-26361 allows unauthenticated remote attackers to factory reset Q-Free MaxTime devices via crafted HTTP requests due to missing authentication...

Feb 12, 2025
CVE-2024-48920
9.1

This vulnerability in PutongOJ online judging software allows unprivileged users to escalate privileges by constructing malicious requests. Attackers ...

Oct 17, 2024
CVE-2024-35293
9.1

CVE-2024-35293 is a critical missing authentication vulnerability in Schneider Electric devices that allows unauthenticated remote attackers to reboot...

Oct 2, 2024
CVE-2024-6592
9.1

This CVE describes an authentication bypass vulnerability in WatchGuard's Single Sign-On system. Attackers can exploit incorrect authorization in prot...

Sep 25, 2024
CVE-2024-8956
9.1

PTZOptics PT30X-SDI/NDI cameras with firmware before 6.3.40 have an authentication bypass vulnerability in the param.cgi endpoint. Attackers can remot...

Sep 17, 2024
CVE-2024-3279
9.1

This vulnerability allows unauthenticated attackers to import malicious database files into the anything-llm application, potentially deleting or spoo...

Aug 12, 2024
CVE-2020-26942
9.1

CVE-2020-26942 is an authentication bypass vulnerability in Axigen Mail Server that allows unauthenticated attackers to reset the administrator passwo...

Mar 21, 2024
CVE-2023-51947
9.1

This vulnerability allows remote attackers to read and modify data without authentication due to improper access control in the nasSvr.php component o...

Jan 19, 2024
CVE-2023-43271
9.1

This vulnerability allows attackers to bypass access controls on the 70mai A500S driving recorder and directly delete video files via FTP and other pr...

Oct 9, 2023
CVE-2023-44152
9.1

This vulnerability allows attackers to bypass authentication mechanisms in Acronis Cyber Protect 15, potentially leading to unauthorized access, sensi...

Sep 27, 2023
CVE-2023-43644
9.1

CVE-2023-43644 is an authentication bypass vulnerability in sing-box proxy software that allows attackers to bypass SOCKS5 inbound authentication. Thi...

Sep 25, 2023
CVE-2023-38028
9.1

Saho ADM100 and ADM-100FP attendance devices have insufficient authentication, allowing unauthenticated remote attackers to bypass authentication and ...

Aug 28, 2023
CVE-2023-0102
9.1

This vulnerability in LS ELECTRIC XBC-DN32U programmable logic controllers allows unauthenticated attackers to delete arbitrary files on the device. T...

Feb 15, 2023
CVE-2023-22804
9.1

This vulnerability allows unauthenticated attackers to create administrative accounts on LS ELECTRIC XBC-DN32U PLCs running OS version 01.80. Attacker...

Feb 15, 2023
CVE-2022-36129
9.1

HashiCorp Vault Enterprise clusters using Integrated Storage expose an unauthenticated API endpoint that allows attackers to override a node's voter s...

Jul 26, 2022
CVE-2022-29951
9.1

CVE-2022-29951 is an authentication bypass vulnerability in JTEKT TOYOPUC PLCs that allows attackers to execute engineering functions without credenti...

Jul 26, 2022

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 674 CVEs classified as CWE-306, with 324 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free