CWE-306: Missing Authentication
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Yearly Trend
Top Affected Vendors
All Missing Authentication CVEs (675)
This vulnerability in SIMATIC Process Historian allows unauthenticated attackers to manipulate historical process data through an interface lacking au...
Oct 12, 2021This vulnerability allows remote attackers to execute arbitrary commands within running containers on OpenShift bootstrap nodes during cluster install...
Feb 23, 2021This vulnerability allows information disclosure when user-level drivers perform QFPROM read/write operations on Fuse regions in Qualcomm chipsets. It...
Nov 4, 2025This vulnerability allows attackers to restore system backups without proper permission validation, potentially leading to account takeover and unauth...
Oct 22, 2021SAP Plant Connectivity (PCo) 15.5 and Production Connector for SAP Digital Manufacturing 1.0 fail to validate JWT signatures in HTTP requests, allowin...
Jun 13, 2023This Android vulnerability allows malicious apps to launch activities from the background without proper permissions, enabling local privilege escalat...
Dec 8, 2025A missing authentication vulnerability in Synology BeeDrive desktop software allows local users to execute arbitrary code without proper authenticatio...
Dec 4, 2025This vulnerability allows local attackers to bypass authentication in Vasion Print (formerly PrinterLogic) by preloading a malicious shared object tha...
Sep 19, 2025This vulnerability allows an authenticated attacker on a Windows system to exploit a missing authentication check in the StateRepository API to elevat...
Aug 12, 2025This vulnerability allows a low-privileged local attacker to exploit improper permissions on nssm.exe (Non-Sucking Service Manager) to escalate privil...
Aug 12, 2025The Archify application on macOS contains a local privilege escalation vulnerability where any local process can connect to its privileged helper tool...
Jun 11, 2025This vulnerability allows local attackers to escalate privileges to SYSTEM level on Y Soft SAFEQ 6 servers. The JMX service on port 9696 lacks authent...
Oct 22, 2024This CVE describes an elevation of privilege vulnerability in the Windows Update Stack. An authenticated attacker could exploit this to gain SYSTEM-le...
Apr 9, 2024CVE-2022-43554 is a local privilege escalation vulnerability in Ivanti Avalanche Smart Device Service where missing authentication allows local attack...
Nov 3, 2023A local attacker can change the update source in IGSS Update Service without authentication, potentially leading to remote code execution by forcing u...
Sep 14, 2023This CVE describes a privilege escalation vulnerability in Cacti where low-privileged Windows users can create arbitrary PHP files in web directories ...
Sep 5, 2023This vulnerability allows unauthenticated remote attackers to execute arbitrary Python code with SYSTEM privileges on Inductive Automation Ignition in...
Jul 25, 2022This vulnerability allows an attacker to execute arbitrary code by tricking a user or system into opening a specially crafted DWG file. It affects app...
Jul 17, 2022CVE-2021-33658 is a privilege escalation vulnerability in atune where local users can use curl to access the atune URL interface without authenticatio...
Mar 11, 2022CVE-2022-24396 is an authentication bypass vulnerability in SAP FRUN Simple Diagnostics Agent versions 1.0 through 1.57. Attackers can access administ...
Mar 10, 2022This vulnerability allows an unauthenticated local attacker to send active help commands to Eclipse Platform processes, potentially executing arbitrar...
Mar 9, 2021OpenClaw sandbox browser bridge server accepts requests without gateway authentication, allowing local attackers to access browser control endpoints. ...
Mar 5, 2026CVE-2025-1272 is a Linux kernel vulnerability where lockdown mode is disabled without warning in Fedora Linux kernel versions 6.12+, allowing attacker...
Feb 18, 2026This vulnerability in JetBrains YouTrack allows unauthorized deletion of issues due to missing permission checks in the API. Any YouTrack instance wit...
May 20, 2025A missing authentication vulnerability in Samsung Galaxy Themes Service allows local attackers to delete arbitrary non-preloaded applications. This af...
Jul 6, 2023This vulnerability allows attackers to inject arbitrary keystrokes into JXL 9 Inch Car Android Double Din Player devices by spoofing a Bluetooth HID d...
Dec 4, 2025This vulnerability affects multiple Siemens LOGO! programmable logic controller models, allowing unauthenticated remote attackers to manipulate device...
Nov 11, 2025This vulnerability allows attackers with address book access to modify SMB/FTP settings on affected Xerox printers, potentially redirecting scans and ...
Feb 3, 2025This vulnerability allows attackers with physical access to the JTAG port on Nuki smart lock devices to bypass hardware and software security protecti...
May 14, 2024This vulnerability in Parse Dashboard's AI Agent API endpoint allows unauthenticated remote attackers to perform arbitrary read and write operations o...
Feb 25, 2026CVE-2026-27584 is an authentication bypass vulnerability in ActualBudget server that allows unauthenticated attackers to access sensitive bank account...
Feb 24, 2026OpenClaw versions 2026.2.13 and below with the @openclaw/voice-call plugin allow unauthenticated attackers to forge Telnyx webhook events when telnyx....
Feb 19, 2026This vulnerability allows any pod within a Kubernetes cluster to send unauthorized AdmissionReview requests to Yoke's Air Traffic Controller webhook e...
Feb 12, 2026This vulnerability in Sliver C2 framework allows unauthenticated attackers to create unlimited DNS sessions without OTP validation, leading to memory ...
Feb 9, 2026CVE-2022-50977 allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via HTTP requests. Th...
Feb 2, 2026This vulnerability allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via Modbus TCP. I...
Feb 2, 2026This vulnerability allows remote attackers to download router configuration files without authentication on Tenda D151 and D301 routers. Attackers can...
Jan 21, 2026The Gotac Statistics Database System has a Missing Authentication vulnerability (CWE-306) that allows unauthenticated remote attackers to directly que...
Jan 16, 2026Vivotek IP7137 cameras with firmware version 0200a allow unauthenticated access to live RTSP video feeds on port 8554. This affects all users of these...
Jan 9, 2026This vulnerability allows unauthenticated remote attackers to access live radio stream information from SOUND4 IMPACT/FIRST/PULSE/Eco systems. Attacke...
Dec 30, 2025Pexip Infinity installations before version 39.0 have an internal API vulnerability where critical functions lack authentication. This allows an attac...
Dec 25, 2025CVE-2025-3232 is an authentication bypass vulnerability in Mitsubishi Electric products that allows remote unauthenticated attackers to execute arbitr...
Dec 24, 2025D-Link DSL-124 routers running ME_1.00 firmware contain an unauthenticated configuration file disclosure vulnerability. Attackers can retrieve complet...
Dec 22, 2025This authentication bypass vulnerability in Screen SFT DAB 600/C devices allows attackers to reset device configurations without valid credentials by ...
Dec 22, 2025This authentication bypass vulnerability in Screen SFT DAB 600/C firmware allows attackers to change the admin password without providing current cred...
Dec 22, 2025This authentication bypass vulnerability in Screen SFT DAB 600/C firmware allows attackers to change user passwords without proper authentication by e...
Dec 22, 2025An authentication bypass vulnerability in Open-WebUI's /api/config endpoint allows unauthenticated remote attackers to access sensitive system configu...
Dec 18, 2025This vulnerability allows unauthenticated attackers to cause denial of service on Socomec DIRIS Digiware M-70 devices by sending a specific sequence o...
Dec 1, 2025This vulnerability allows unauthenticated attackers to cause denial of service on Socomec DIRIS Digiware M-70 devices by sending a specially crafted M...
Dec 1, 2025This vulnerability allows unauthenticated attackers to cause denial of service on Socomec DIRIS Digiware M-70 devices by sending a specific sequence o...
Dec 1, 2025About Missing Authentication (CWE-306)
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Our database tracks 675 CVEs classified as CWE-306, with 325 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.
External reference: View CWE-306 on MITRE CWE →
Monitor Missing Authentication Vulnerabilities
Get alerted when new Missing Authentication CVEs affect your infrastructure.
Start Monitoring Free