← Back to feed Search feed

CWE-306 Missing Authentication vulnerabilities

38 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-14446IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminisCRITICAL9.821%ileNVD2026-07-28
CVE-2026-68502LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.CRITICAL9.842%ileNVD2026-07-30
CVE-2026-14529IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 tCRITICAL9.426%ileNVD2026-07-29
CVE-2026-60112AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenCRITICAL9.334%ileNVD2026-07-29
CVE-2026-60113AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulneraCRITICAL9.334%ileNVD2026-07-29
CVE-2026-67426Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verificaCRITICAL9.321%ileNVD2026-07-29
CVE-2026-44090Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected frCRITICAL9.333%ileNVD2026-07-30
CVE-2026-44101Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the CRITICAL9.333%ileNVD2026-07-30
CVE-2026-67208Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execCRITICAL9.362%ileNVD2026-07-30
CVE-2026-67594Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attacCRITICAL9.337%ileNVD2026-07-30
CVE-2026-41452Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticatedCRITICAL9.348%ileNVD2026-08-03
CVE-2026-61514Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthentCRITICAL9.3NVD2026-08-04
CVE-2026-69110OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackerCRITICAL9.3NVD2026-08-04
CVE-2026-62325goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserverCRITICAL9.127%ileNVD2026-07-28
CVE-2026-16771In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on HIGH8.816%ileNVD2026-07-28
CVE-2026-44100The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to diHIGH8.820%ileNVD2026-07-30
CVE-2026-54367CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, wHIGH8.89%ileNVD2026-07-30
CVE-2026-16236The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5HIGH8.847%ileNVD2026-07-31
CVE-2026-54365CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unautheHIGH8.712%ileNVD2026-07-30
CVE-2026-67349OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environmHIGH8.721%ileNVD2026-07-30
CVE-2026-12562The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting fullHIGH8.720%ileNVD2026-07-30
CVE-2026-69091Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only HIGH8.728%ileNVD2026-08-03
CVE-2026-67610OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoiHIGH8.625%ileNVD2026-08-03
CVE-2026-12722Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel aHIGH8.217%ileNVD2026-07-30
CVE-2026-58071A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance AHIGH8.2NVD2026-08-04
CVE-2026-24079Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.HIGH8.1NVD2026-08-04
CVE-2026-47858Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicatiHIGH8.010%ileNVD2026-07-30
CVE-2026-59913Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for CritiHIGH7.82%ileNVD2026-08-03
CVE-2026-68578ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine pHIGH7.712%ileNVD2026-08-02
CVE-2026-5057ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackeHIGH7.539%ileNVD2026-07-29
CVE-2026-28814Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sHIGH7.525%ileNVD2026-07-30
CVE-2026-15978SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endHIGH7.522%ileNVD2026-07-30
CVE-2026-65310ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuHIGH7.524%ileNVD2026-07-31
CVE-2026-14976IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colleHIGH7.19%ileNVD2026-07-28
CVE-2026-17348In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's befMEDIUM6.916%ileNVD2026-07-31
CVE-2026-65311The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoiMEDIUM5.319%ileNVD2026-07-31
CVE-2026-13306Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present atMEDIUM4.38%ileNVD2026-07-29
FG-IR-26-125Missing Authentication for critical function in CAPWAP daemonUNKNOWNFortinet2026-04-14