← Back
CWE-306

2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,579)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pingidentity
1Pingid Integration For Windows Login
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to expl...Show more
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to code executed as SYSTEM by the PingID Windows Login application, or even a denial of service for offline security key authentication.Show less
1Ilias
1Ilias
Jun 17, 2026
Jun 29, 2022
N/A· v4
4.3 MEDIUM· v3
7.5 HIGH· v2
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
1Nagios
1Nagios Xi
Jun 17, 2026
Jun 29, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
1Illumina
1Local Run Manager
Jun 17, 2026
Jun 24, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.
1Shinasys
3Sihas Acm 300 Firmware
Sihas Gcm 300 FirmwareSihas Sgw 300 Firmware
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
1Suse
1Manager Server
Jul 7, 2026
Jun 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This i...Show more
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.Show less
1Iobit
1Iotransfer
Jul 9, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which...Show more
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.Show less
1Ariang Project
1Ariang
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.
1Splunk
1Splunk
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for...Show more
Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/ConfigDSDCAuthEnhancements#Configure_authentication_for_deployment_servers_and_clients). Once enabled, deployment servers can manage only Universal Forwarder versions 9.0 and higher. Though the vulnerability does not directly affect Universal Forwarders, remediation requires updating all Universal Forwarders that the deployment server manages to version 9.0 or higher prior to enabling the remediation.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
1Siemens
1Sinema Remote Connect Server
Jun 17, 2026
Jun 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allo...Show more
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allow an attacker to change the permissions of any user and gain the privileges of an administrative user.Show less
1Siemens
1Sicam Gridedge Essential
Jun 17, 2026
Jun 14, 2022
9.3 CRITICAL· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attack...Show more
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions.Show less
1Siemens
1Sicam Gridedge Essential
Jun 17, 2026
Jun 14, 2022
8.6 HIGH· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attack...Show more
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case that user's id is known.Show less
1Envoyproxy
1Envoy
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a...Show more
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.Show less
12code
1Wpqa Builder
Jun 17, 2026
Jun 8, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on t...Show more
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.Show less
1Totolink
1Ex1200t Firmware
Jun 17, 2026
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
1Totolink
1Ex1200t Firmware
Jun 17, 2026
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
1Totolink
1Ex1200t Firmware
Jun 17, 2026
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
1Owllabs
1Meeting Owl Pro Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message.
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.