CWE-306 · 2,746 records
Missing authentication for critical function
Why does it happen?
A function added for development or support ships to production without authentication. It often relies on the assumption that it is “only reachable from the internal network.”
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
// Added for the support teamapp.post("/maintenance/reset", resetDevice);Fixed
if (config.maintenanceEnabled) { app.post( "/maintenance/reset", requireSession, requireRole("admin"), resetDevice );}How to prevent it
- 01Remove maintenance and debugging functions from production builds.
- 02If one must stay, protect it with an authorization check and a separate configuration flag.
- 03Never treat network location as a substitute for authentication.
CVEs in this class
2,751 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-32433Weaponized | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Critical10.0 | KEV | 98.8% | Apr 16, 2025 |
99Now | CVE-2025-3248Weaponized | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codelangflow · langflow · CWE-306 | Critical9.8 | KEV | 100.0% | Apr 7, 2025 |
99Now | CVE-2022-1388Weaponized | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior f5 · big-ip access policy manager · CWE-306 | Critical9.8 | KEV | 100.0% | May 5, 2022 |
99Now | CVE-2021-37415Weaponized | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authenticatiozohocorp · manageengine servicedesk plus · CWE-306 | Critical9.8 | KEV | 99.8% | Sep 1, 2021 |
99Now | CVE-2020-13927Weaponized | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Critical9.8 | KEV | 99.8% | Nov 10, 2020 |
99Now | CVE-2022-21587Weaponized | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).oracle · e-business suite · CWE-306 | Critical9.8 | KEV | 98.3% | Oct 18, 2022 |
98Now | CVE-2020-6207Weaponized | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication forsap · solution manager · CWE-306 | Critical9.8 | KEV | 98.1% | Mar 10, 2020 |
98Now | CVE-2026-20253Weaponized | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Critical9.8 | KEV | 96.9% | Jun 10, 2026 |
98Now | CVE-2021-35587Weaponized | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).oracle · access manager · CWE-306 | Critical9.8 | KEV | 96.3% | Jan 19, 2022 |
98Now | CVE-2020-6287Weaponized | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows ansap · netweaver application server java · CWE-306 | Critical10.0 | KEV | 94.7% | Jul 14, 2020 |
97Now | CVE-2024-0012Weaponized | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)paloaltonetworks · pan-os · CWE-306 | Critical9.3 | KEV | 99.9% | Nov 18, 2024 |
97Now | CVE-2026-41940Weaponized | WebPros cPanel and WHM Authentication Bypass via Login Flowcpanel · cpanel · CWE-306 | Critical9.3 | KEV | 98.5% | Apr 29, 2026 |
97Now | CVE-2024-47575Weaponized | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fofortinet · fortimanager · CWE-306 | Critical9.8 | KEV | 94.8% | Oct 23, 2024 |
97Now | CVE-2021-44077Weaponized | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unzohocorp · manageengine servicedesk plus · CWE-306 | Critical9.8 | KEV | 93.3% | Nov 29, 2021 |
97Now | CVE-2024-11680Weaponized | ProjectSend Unauthenticated Configuration Modificationprojectsend · projectsend · CWE-306 | Critical9.8 | KEV | 91.7% | Nov 26, 2024 |
96Now | CVE-2020-3952Weaponized | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)vmware · vcenter server · CWE-306 | Critical9.8 | KEV | 90.4% | Apr 10, 2020 |
96Now | CVE-2025-61757Weaponized | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).oracle · identity manager · CWE-306 | Critical9.8 | KEV | 88.6% | Oct 21, 2025 |
95Now | CVE-2025-0108Weaponized | PAN-OS: Authentication Bypass in the Management Web Interfacepaloaltonetworks · pan-os · CWE-306 | High8.8 | KEV | 98.5% | Feb 12, 2025 |
95Now | CVE-2024-5910Weaponized | Expedition: Missing Authentication Leads to Admin Account Takeoverpaloaltonetworks · expedition · CWE-306 | Critical9.3 | KEV | 91.7% | Jul 10, 2024 |
95Now | CVE-2022-26143Weaponized | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers tomitel · micollab · CWE-306 | Critical9.8 | KEV | 87.3% | Mar 10, 2022 |
95Now | CVE-2024-51567Weaponized | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication andcyberpanel · cyberpanel · CWE-306 | Critical9.8 | KEV | 86.6% | Oct 29, 2024 |
93Now | CVE-2026-24423Weaponized | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIsmartertools · smartermail · CWE-306 | Critical9.3 | KEV | 88.2% | Jan 23, 2026 |
90Now | CVE-2017-10271Weaponized | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security).oracle · weblogic server · CWE-306 | High7.5 | KEV | 100.0% | Oct 19, 2017 |
85Now | CVE-2022-24990Weaponized | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/aterra-master · terramaster operating system · CWE-306 | High7.5 | KEV | 83.2% | Feb 7, 2023 |
84Now | CVE-2023-27532Weaponized | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.veeam · veeam backup \& replication · CWE-306 | High7.5 | KEV | 81.3% | Mar 10, 2023 |
- CVE-2025-32433100Now
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CriticalCVSS 10.0KEVWeaponizedEPSS 99%erlang · erlang\/otpApr 16, 2025
- CVE-2025-324899Now
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
CriticalCVSS 9.8KEVWeaponizedEPSS 100%langflow · langflowApr 7, 2025
- CVE-2022-138899Now
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerMay 5, 2022
- CVE-2021-3741599Now
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authenticatio
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine servicedesk plusSep 1, 2021
- CVE-2020-1392799Now
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · airflowNov 10, 2020
- CVE-2022-2158799Now
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · e-business suiteOct 18, 2022
- CVE-2020-620798Now
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for
CriticalCVSS 9.8KEVWeaponizedEPSS 98%sap · solution managerMar 10, 2020
- CVE-2026-2025398Now
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
CriticalCVSS 9.8KEVWeaponizedEPSS 97%splunk · splunkJun 10, 2026
- CVE-2021-3558798Now
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).
CriticalCVSS 9.8KEVWeaponizedEPSS 96%oracle · access managerJan 19, 2022
- CVE-2020-628798Now
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an
CriticalCVSS 10.0KEVWeaponizedEPSS 95%sap · netweaver application server javaJul 14, 2020
- CVE-2024-001297Now
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
CriticalCVSS 9.3KEVWeaponizedEPSS 100%paloaltonetworks · pan-osNov 18, 2024
- CVE-2026-4194097Now
WebPros cPanel and WHM Authentication Bypass via Login Flow
CriticalCVSS 9.3KEVWeaponizedEPSS 99%cpanel · cpanelApr 29, 2026
- CVE-2024-4757597Now
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fo
CriticalCVSS 9.8KEVWeaponizedEPSS 95%fortinet · fortimanagerOct 23, 2024
- CVE-2021-4407797Now
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to un
CriticalCVSS 9.8KEVWeaponizedEPSS 93%zohocorp · manageengine servicedesk plusNov 29, 2021
- CVE-2024-1168097Now
ProjectSend Unauthenticated Configuration Modification
CriticalCVSS 9.8KEVWeaponizedEPSS 92%projectsend · projectsendNov 26, 2024
- CVE-2020-395296Now
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)
CriticalCVSS 9.8KEVWeaponizedEPSS 90%vmware · vcenter serverApr 10, 2020
- CVE-2025-6175796Now
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).
CriticalCVSS 9.8KEVWeaponizedEPSS 89%oracle · identity managerOct 21, 2025
- CVE-2025-010895Now
PAN-OS: Authentication Bypass in the Management Web Interface
HighCVSS 8.8KEVWeaponizedEPSS 98%paloaltonetworks · pan-osFeb 12, 2025
- CVE-2024-591095Now
Expedition: Missing Authentication Leads to Admin Account Takeover
CriticalCVSS 9.3KEVWeaponizedEPSS 92%paloaltonetworks · expeditionJul 10, 2024
- CVE-2022-2614395Now
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to
CriticalCVSS 9.8KEVWeaponizedEPSS 87%mitel · micollabMar 10, 2022
- CVE-2024-5156795Now
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and
CriticalCVSS 9.8KEVWeaponizedEPSS 87%cyberpanel · cyberpanelOct 29, 2024
- CVE-2026-2442393Now
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
CriticalCVSS 9.3KEVWeaponizedEPSS 88%smartertools · smartermailJan 23, 2026
- CVE-2017-1027190Now
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security).
HighCVSS 7.5KEVWeaponizedEPSS 100%oracle · weblogic serverOct 19, 2017
- CVE-2022-2499085Now
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/a
HighCVSS 7.5KEVWeaponizedEPSS 83%terra-master · terramaster operating systemFeb 7, 2023
- CVE-2023-2753284Now
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.
HighCVSS 7.5KEVWeaponizedEPSS 81%veeam · veeam backup \& replicationMar 10, 2023