Missing Authentication for Critical Function

CWE-306 · 15 records · 11 with a public proof-of-concept

Records the NVD classes as Missing Authentication for Critical Function (CWE-306), highest CVSS first.

  1. CRITICAL 9.8CVE-2026-71289public PoC

    The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RA

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.8CVE-2026-71262public PoC

    IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, le

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.8CVE-2026-71214public PoC

    The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over

    AI risk analysis on Exploit-DB.ai →

  4. CRITICAL 9.8CVE-2026-70552public PoC

    MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving t

    AI risk analysis on Exploit-DB.ai →

  5. CRITICAL 9.8CVE-2026-69703public PoC

    Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attack

    AI risk analysis on Exploit-DB.ai →

  6. CRITICAL 9.8CVE-2026-63455

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view

    AI risk analysis on Exploit-DB.ai →

  7. CRITICAL 9.8CVE-2026-61514

    Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can ex

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 8.8CVE-2026-60009public PoC

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp,

    theia

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 8.1CVE-2026-24079

    Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

    ar8035 firmware · ar8035 · csra6620 firmware · csra6620 · csra6640 firmware · csra6640

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 7.5CVE-2026-61891public PoC

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without

    theia

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 7.5CVE-2026-71241public PoC

    Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are se

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 7.3CVE-2026-25703public PoC

    NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 7.3CVE-2026-18810public PoC

    A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early ab

    AI risk analysis on Exploit-DB.ai →

  14. MEDIUM 5.3CVE-2026-71203public PoC

    changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.c

    AI risk analysis on Exploit-DB.ai →

  15. UNSCOREDCVE-2026-58071

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.

    AI risk analysis on Exploit-DB.ai →