CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

675
Total CVEs
325
Critical
243
High
8.5
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Sap 11
3 Socomec 10
4 Siemens 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Vasion 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (675)

CVE-2023-22906
8.8

This vulnerability allows unauthenticated remote attackers to gain root access to affected Hero Qubo HCD01_02 devices via TELNET. The devices have TEL...

Jul 4, 2023
CVE-2023-27980
8.8

This vulnerability allows unauthenticated attackers to create malicious report files in IGSS project directories via the Data Server TCP interface. Wh...

Mar 21, 2023
CVE-2022-32251
8.8

CVE-2022-32251 is an authentication bypass vulnerability in Siemens SINEMA Remote Connect Server that allows attackers to modify user permissions with...

Jun 14, 2022
CVE-2020-27376
8.8

The Dr Trust USA iCheck Connect BP Monitor version 1.2.1 lacks proper authentication mechanisms, allowing unauthorized access to device functions and ...

Apr 7, 2022
CVE-2021-33008
8.8

CVE-2021-33008 is an authentication bypass vulnerability in AVEVA System Platform versions 2017 through 2020 R2 P01. It allows unauthenticated attacke...

Apr 4, 2022
CVE-2022-25008
8.8

This CVE describes a missing authentication mechanism in totolink EX300_v2 and EX1200T routers, allowing attackers to access administrative functions ...

Mar 30, 2022
CVE-2021-23843
8.8

This vulnerability allows attackers on the local network to bypass password protection on Bosch AMC2 device configuration tools, enabling unauthorized...

Jan 19, 2022
CVE-2021-27255
8.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on NETGEAR R7800 routers. The flaw exists in...

Mar 5, 2021
CVE-2021-25312
8.8

This vulnerability in HTCondor allows authenticated users to submit jobs as other users on the system due to a flaw in the IDTOKENS authentication met...

Jan 27, 2021
CVE-2025-23293
8.7

The NVIDIA Delegated Licensing Service vulnerability allows authenticated users or attackers to perform unauthorized actions, potentially leading to i...

Sep 30, 2025
CVE-2025-8279
8.7

This vulnerability allows attackers to execute arbitrary GraphQL queries on GitLab Language Server due to insufficient input validation. This could le...

Jul 28, 2025
CVE-2026-26125
8.6

This vulnerability allows attackers to elevate privileges in Payment Orchestrator Service, potentially gaining unauthorized access to payment processi...

Mar 5, 2026
CVE-2025-55221
8.6

An unauthenticated denial of service vulnerability exists in Socomec DIRIS Digiware M-70 devices running version 1.6.9. Attackers can send specially c...

Dec 1, 2025
CVE-2025-55222
8.6

An unauthenticated denial-of-service vulnerability exists in Socomec DIRIS Digiware M-70 devices running version 1.6.9. Attackers can send specially c...

Dec 1, 2025
CVE-2025-23417
8.6

An unauthenticated denial-of-service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 devices. Attackers c...

Dec 1, 2025
CVE-2024-48882
8.6

An unauthenticated denial-of-service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 devices. Attackers can send s...

Dec 1, 2025
CVE-2025-34225
8.6

This CVE describes an unauthenticated server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) Virtual Appliance Host ...

Sep 29, 2025
CVE-2025-34231
8.6

This CVE describes an unauthenticated server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) Virtual Appliance Host ...

Sep 29, 2025
CVE-2025-21355
8.6

CVE-2025-21355 is a missing authentication vulnerability in Microsoft Bing that allows unauthorized attackers to execute arbitrary code over the netwo...

Feb 19, 2025
CVE-2024-12757
8.6

CVE-2024-12757 is an authentication bypass vulnerability in Nedap Librix Ecoreader that allows unauthenticated attackers to access critical functions....

Jan 17, 2025
CVE-2024-35277
8.6

This vulnerability allows unauthenticated attackers to access configuration data of managed devices by sending specially crafted packets to Fortinet F...

Jan 14, 2025
CVE-2024-11980
8.6

Billion Electric routers have a missing authentication vulnerability that allows unauthenticated remote attackers to access administrative functions. ...

Nov 29, 2024
CVE-2024-43798
8.6

Chisel servers using the AUTH environment variable for authentication are vulnerable to complete authentication bypass, allowing any unauthenticated u...

Aug 26, 2024
CVE-2023-22441
8.6

This vulnerability allows remote attackers to bypass authentication on Seiko Solutions SkyBridge devices, enabling unauthorized access to critical fun...

May 10, 2023
CVE-2023-25013
8.6

This vulnerability in the femanager extension for TYPO3 allows unauthenticated attackers to reset passwords for all frontend users due to missing acce...

Feb 2, 2023
CVE-2021-41266
8.6

CVE-2021-41266 is an authentication bypass vulnerability in MinIO Console when external identity provider (IDP) authentication is enabled. Attackers c...

Nov 15, 2021
CVE-2021-29442
8.6

CVE-2021-29442 is an authentication bypass vulnerability in Nacos that allows unauthenticated attackers to access the /derby endpoint, enabling databa...

Apr 27, 2021
CVE-2023-1837
8.5

This vulnerability allows attackers to bypass authentication in HYPR Server by exploiting missing authentication checks in Legacy APIs. It affects all...

May 23, 2023
CVE-2026-27182
8.4

Saturn Remote Mouse Server has a critical command injection vulnerability that allows unauthenticated attackers on the local network to execute arbitr...

Feb 18, 2026
CVE-2024-9919
8.4

This vulnerability allows unauthenticated attackers to delete directories via the uninstall API endpoint in parisneo/lollms-webui. Attackers can explo...

Mar 20, 2025
CVE-2025-27256
8.3

This vulnerability allows attackers to bypass SSH authentication in GE Vernova Enervista UR Setup software, enabling man-in-the-middle attacks. Attack...

Mar 10, 2025
CVE-2025-8450
8.2

An improper access control vulnerability in Fortra's FileCatalyst Workflow component allows unauthenticated attackers to upload arbitrary files via th...

Aug 19, 2025
CVE-2025-41654
8.2

An unauthenticated remote attacker can exploit this SNMP vulnerability to access process information and trigger a system reboot via watchdog. This af...

May 26, 2025
CVE-2025-25060
8.2

A missing authentication vulnerability in AssetView and AssetView CLOUD allows unauthenticated remote attackers to access and delete files on the serv...

Apr 2, 2025
CVE-2024-8053
8.2

This vulnerability in open-webui v0.3.10 allows unauthenticated attackers to access the PDF generation endpoint, potentially causing denial of service...

Mar 20, 2025
CVE-2024-10776
8.2

This vulnerability allows unauthorized users to deploy, remove, start, reload, or stop Lua applications via AppManager in SICK products. Attackers can...

Dec 6, 2024
CVE-2022-34321
8.2

Apache Pulsar Proxy has an improper authentication vulnerability that allows unauthenticated access to the /proxy-stats endpoint. This exposes connect...

Mar 12, 2024
CVE-2023-46381
8.2

LOYTEC building automation devices lack authentication for the LWEB-802 web interface via specific URIs, allowing unauthenticated attackers to modify ...

Nov 4, 2023
CVE-2023-34392
8.2

This vulnerability allows attackers to execute arbitrary commands on managed devices through the SEL-5037 Grid Configurator without proper authenticat...

Aug 31, 2023
CVE-2022-2138
8.2

This vulnerability allows attackers to bypass authentication in affected products, potentially enabling them to read or modify sensitive data, execute...

Jul 22, 2022
CVE-2021-27963
8.2

CVE-2021-27963 is an authentication bypass vulnerability in SonLogger that allows unauthenticated attackers to create new user accounts with administr...

Mar 5, 2021
CVE-2026-28472
8.1

OpenClaw versions before 2026.2.2 have an authentication bypass vulnerability in the WebSocket gateway connection handshake. Attackers can connect wit...

Mar 5, 2026
CVE-2025-7679
8.1

CVE-2025-7679 is an authentication bypass vulnerability in the ASPECT system that allows unauthorized users to access protected functionality without ...

Aug 11, 2025
CVE-2025-3319
8.1

IBM Spectrum Protect Server versions 8.1 through 8.1.26 contain an authentication bypass vulnerability due to improper session authentication. Attacke...

Jun 20, 2025
CVE-2024-42455
8.1

A vulnerability in Veeam Backup & Replication allows low-privileged authenticated users to exploit insecure deserialization via remoting services, ena...

Dec 4, 2024
CVE-2024-5718
8.1

CVE-2024-5718 is an unauthenticated remote code execution vulnerability in Logsign Unified SecOps Platform's cluster HTTP API. Attackers can execute a...

Nov 22, 2024
CVE-2024-41967
8.1

A low-privileged remote attacker can modify the boot mode configuration of affected devices, potentially altering firmware upgrade processes or causin...

Nov 18, 2024
CVE-2024-21146
8.1

This vulnerability in Oracle Trade Management allows authenticated attackers with low privileges to perform unauthorized data manipulation and access ...

Jul 16, 2024
CVE-2023-2781
8.1

This vulnerability allows unauthenticated attackers to bypass authentication in the User Email Verification for WooCommerce WordPress plugin by exploi...

Jun 3, 2023
CVE-2022-26925
8.1

CVE-2022-26925 is a Windows Local Security Authority (LSA) spoofing vulnerability that allows an authenticated attacker to impersonate any user on a d...

May 10, 2022

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 675 CVEs classified as CWE-306, with 325 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free