CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

675
Total CVEs
325
Critical
243
High
8.5
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Sap 11
3 Socomec 10
4 Siemens 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Vasion 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (675)

CVE-2021-27395
8.1

This vulnerability in SIMATIC Process Historian allows unauthenticated attackers to manipulate historical process data through an interface lacking au...

Oct 12, 2021
CVE-2021-20198
8.1

This vulnerability allows remote attackers to execute arbitrary commands within running containers on OpenShift bootstrap nodes during cluster install...

Feb 23, 2021
CVE-2025-47357
8.0

This vulnerability allows information disclosure when user-level drivers perform QFPROM read/write operations on Fuse regions in Qualcomm chipsets. It...

Nov 4, 2025
CVE-2021-42539
8.0

This vulnerability allows attackers to restore system backups without proper permission validation, potentially leading to account takeover and unauth...

Oct 22, 2021
CVE-2023-2827
7.9

SAP Plant Connectivity (PCo) 15.5 and Production Connector for SAP Digital Manufacturing 1.0 fail to validate JWT signatures in HTTP requests, allowin...

Jun 13, 2023
CVE-2025-48572
KEV 7.8

This Android vulnerability allows malicious apps to launch activities from the background without proper permissions, enabling local privilege escalat...

Dec 8, 2025
CVE-2025-54158
7.8

A missing authentication vulnerability in Synology BeeDrive desktop software allows local users to execute arbitrary code without proper authenticatio...

Dec 4, 2025
CVE-2025-34190
7.8

This vulnerability allows local attackers to bypass authentication in Vasion Print (formerly PrinterLogic) by preloading a malicious shared object tha...

Sep 19, 2025
CVE-2025-53789
7.8

This vulnerability allows an authenticated attacker on a Windows system to exploit a missing authentication check in the StateRepository API to elevat...

Aug 12, 2025
CVE-2025-41686
7.8

This vulnerability allows a low-privileged local attacker to exploit improper permissions on nssm.exe (Non-Sucking Service Manager) to escalate privil...

Aug 12, 2025
CVE-2024-9062
7.8

The Archify application on macOS contains a local privilege escalation vulnerability where any local process can connect to its privileged helper tool...

Jun 11, 2025
CVE-2022-23862
7.8

This vulnerability allows local attackers to escalate privileges to SYSTEM level on Y Soft SAFEQ 6 servers. The JMX service on port 9696 lacks authent...

Oct 22, 2024
CVE-2024-26235
7.8

This CVE describes an elevation of privilege vulnerability in the Windows Update Stack. An authenticated attacker could exploit this to gain SYSTEM-le...

Apr 9, 2024
CVE-2022-43554
7.8

CVE-2022-43554 is a local privilege escalation vulnerability in Ivanti Avalanche Smart Device Service where missing authentication allows local attack...

Nov 3, 2023
CVE-2023-4516
7.8

A local attacker can change the update source in IGSS Update Service without authentication, potentially leading to remote code execution by forcing u...

Sep 14, 2023
CVE-2023-31132
7.8

This CVE describes a privilege escalation vulnerability in Cacti where low-privileged Windows users can create arbitrary PHP files in web directories ...

Sep 5, 2023
CVE-2022-35871
7.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary Python code with SYSTEM privileges on Inductive Automation Ignition in...

Jul 25, 2022
CVE-2022-28809
7.8

This vulnerability allows an attacker to execute arbitrary code by tricking a user or system into opening a specially crafted DWG file. It affects app...

Jul 17, 2022
CVE-2021-33658
7.8

CVE-2021-33658 is a privilege escalation vulnerability in atune where local users can use curl to access the atune URL interface without authenticatio...

Mar 11, 2022
CVE-2022-24396
7.8

CVE-2022-24396 is an authentication bypass vulnerability in SAP FRUN Simple Diagnostics Agent versions 1.0 through 1.57. Attackers can access administ...

Mar 10, 2022
CVE-2020-27225
7.8

This vulnerability allows an unauthenticated local attacker to send active help commands to Eclipse Platform processes, potentially executing arbitrar...

Mar 9, 2021
CVE-2026-28468
7.7

OpenClaw sandbox browser bridge server accepts requests without gateway authentication, allowing local attackers to access browser control endpoints. ...

Mar 5, 2026
CVE-2025-1272
7.7

CVE-2025-1272 is a Linux kernel vulnerability where lockdown mode is disabled without warning in Fedora Linux kernel versions 6.12+, allowing attacker...

Feb 18, 2026
CVE-2025-48391
7.7

This vulnerability in JetBrains YouTrack allows unauthorized deletion of issues due to missing permission checks in the API. Any YouTrack instance wit...

May 20, 2025
CVE-2023-30643
7.7

A missing authentication vulnerability in Samsung Galaxy Themes Service allows local attackers to delete arbitrary non-preloaded applications. This af...

Jul 6, 2023
CVE-2025-63896
7.6

This vulnerability allows attackers to inject arbitrary keystrokes into JXL 9 Inch Car Android Double Din Player devices by spoofing a Bluetooth HID d...

Dec 4, 2025
CVE-2025-40816
7.6

This vulnerability affects multiple Siemens LOGO! programmable logic controller models, allowing unauthenticated remote attackers to manipulate device...

Nov 11, 2025
CVE-2024-12511
7.6

This vulnerability allows attackers with address book access to modify SMB/FTP settings on affected Xerox printers, potentially redirecting scans and ...

Feb 3, 2025
CVE-2022-32503
7.6

This vulnerability allows attackers with physical access to the JTAG port on Nuki smart lock devices to bypass hardware and software security protecti...

May 14, 2024
CVE-2026-27595
7.5

This vulnerability in Parse Dashboard's AI Agent API endpoint allows unauthenticated remote attackers to perform arbitrary read and write operations o...

Feb 25, 2026
CVE-2026-27584
7.5

CVE-2026-27584 is an authentication bypass vulnerability in ActualBudget server that allows unauthenticated attackers to access sensitive bank account...

Feb 24, 2026
CVE-2026-26319
7.5

OpenClaw versions 2026.2.13 and below with the @openclaw/voice-call plugin allow unauthenticated attackers to forge Telnyx webhook events when telnyx....

Feb 19, 2026
CVE-2026-26055
7.5

This vulnerability allows any pod within a Kubernetes cluster to send unauthorized AdmissionReview requests to Yoke's Air Traffic Controller webhook e...

Feb 12, 2026
CVE-2026-25791
7.5

This vulnerability in Sliver C2 framework allows unauthenticated attackers to create unlimited DNS sessions without OTP validation, leading to memory ...

Feb 9, 2026
CVE-2022-50977
7.5

CVE-2022-50977 allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via HTTP requests. Th...

Feb 2, 2026
CVE-2022-50978
7.5

This vulnerability allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via Modbus TCP. I...

Feb 2, 2026
CVE-2021-47802
7.5

This vulnerability allows remote attackers to download router configuration files without authentication on Tenda D151 and D301 routers. Attackers can...

Jan 21, 2026
CVE-2026-1023
7.5

The Gotac Statistics Database System has a Missing Authentication vulnerability (CWE-306) that allows unauthenticated remote attackers to directly que...

Jan 16, 2026
CVE-2025-66049
7.5

Vivotek IP7137 cameras with firmware version 0200a allow unauthenticated access to live RTSP video feeds on port 8554. This affects all users of these...

Jan 9, 2026
CVE-2022-50790
7.5

This vulnerability allows unauthenticated remote attackers to access live radio stream information from SOUND4 IMPACT/FIRST/PULSE/Eco systems. Attacke...

Dec 30, 2025
CVE-2025-66377
7.5

Pexip Infinity installations before version 39.0 have an internal API vulnerability where critical functions lack authentication. This allows an attac...

Dec 25, 2025
CVE-2025-3232
7.5

CVE-2025-3232 is an authentication bypass vulnerability in Mitsubishi Electric products that allows remote unauthenticated attackers to execute arbitr...

Dec 24, 2025
CVE-2023-53974
7.5

D-Link DSL-124 routers running ME_1.00 firmware contain an unauthenticated configuration file disclosure vulnerability. Attackers can retrieve complet...

Dec 22, 2025
CVE-2023-53970
7.5

This authentication bypass vulnerability in Screen SFT DAB 600/C devices allows attackers to reset device configurations without valid credentials by ...

Dec 22, 2025
CVE-2023-53967
7.5

This authentication bypass vulnerability in Screen SFT DAB 600/C firmware allows attackers to change the admin password without providing current cred...

Dec 22, 2025
CVE-2023-53969
7.5

This authentication bypass vulnerability in Screen SFT DAB 600/C firmware allows attackers to change user passwords without proper authentication by e...

Dec 22, 2025
CVE-2025-63391
7.5

An authentication bypass vulnerability in Open-WebUI's /api/config endpoint allows unauthenticated remote attackers to access sensitive system configu...

Dec 18, 2025
CVE-2025-54850
7.5

This vulnerability allows unauthenticated attackers to cause denial of service on Socomec DIRIS Digiware M-70 devices by sending a specific sequence o...

Dec 1, 2025
CVE-2025-54851
7.5

This vulnerability allows unauthenticated attackers to cause denial of service on Socomec DIRIS Digiware M-70 devices by sending a specially crafted M...

Dec 1, 2025
CVE-2025-54848
7.5

This vulnerability allows unauthenticated attackers to cause denial of service on Socomec DIRIS Digiware M-70 devices by sending a specific sequence o...

Dec 1, 2025

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 675 CVEs classified as CWE-306, with 325 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free