Missing Authentication for Critical Function
CWE-306 · 15 records · 11 with a public proof-of-concept
Records the NVD classes as Missing Authentication for Critical Function (CWE-306), highest CVSS first.
- CRITICAL 9.8CVE-2026-71289public PoC
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RA…
- CRITICAL 9.8CVE-2026-71262public PoC
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, le…
- CRITICAL 9.8CVE-2026-71214public PoC
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over…
- CRITICAL 9.8CVE-2026-70552public PoC
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving t…
- CRITICAL 9.8CVE-2026-69703public PoC
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attack…
- CRITICAL 9.8CVE-2026-63455
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view…
- CRITICAL 9.8CVE-2026-61514
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can ex…
- HIGH 8.8CVE-2026-60009public PoC
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, …
theia
- HIGH 8.1CVE-2026-24079
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
ar8035 firmware · ar8035 · csra6620 firmware · csra6620 · csra6640 firmware · csra6640
- HIGH 7.5CVE-2026-61891public PoC
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without…
theia
- HIGH 7.5CVE-2026-71241public PoC
Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are se…
- HIGH 7.3CVE-2026-25703public PoC
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.
- HIGH 7.3CVE-2026-18810public PoC
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early ab…
- MEDIUM 5.3CVE-2026-71203public PoC
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.c…
- UNSCOREDCVE-2026-58071
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.