← Back
CWE-306

2,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
23Lax20 Firmware
R6400 FirmwareR6700 Firmware+20 more
Jun 17, 2026
Mar 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists w...Show more
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15762.Show less
1Apache
1Openmeetings
Jun 17, 2026
Mar 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
1Deltaww
1Infrasuite Device Master
Jun 17, 2026
Mar 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.
1Hgiga
1Powerstation Firmware
Jun 17, 2026
Mar 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerSt...Show more
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Mar 23, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
1Lightcms Project
1Lightcms
Jun 17, 2026
Mar 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Mar 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achie...Show more
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.Show less
1Schneider Electric
3Custom Reports
Igss DashboardIgss Data Server
Jun 17, 2026
Mar 21, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data w...Show more
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).Show less
1Schneider Electric
3Custom Reports
Igss DashboardIgss Data Server
Jun 17, 2026
Mar 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead...Show more
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior)Show less
1Arraynetworks
1Arrayos Ag
Jun 17, 2026
Mar 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication....Show more
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Mar 14, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure h...Show more
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive server data. Show less
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
1Ibm
1Observability With Instana
Jun 17, 2026
Mar 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could acce...Show more
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.Show less
1Zbt
1We1626 Firmware
Jul 9, 2026
Mar 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
1Vmware
1Workspace One Content
Jun 17, 2026
Feb 28, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
1Wago
7751 9301 Firmware
752 8303/8000 002 FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
1Wago
7751 9301 Firmware
752 8303/8000 002 FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read an...Show more
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.Show less
1Aremis
1Aremis 4 Nomads
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker...Show more
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.Show less
1Sick
2Fx0 Gent00000 Firmware
Fx0 Gent00010 Firmware
Jun 17, 2026
Feb 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands t...Show more
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.Show less