Skip to content
Noroxi

CWE-306 · 2,746 records

Missing authentication for critical function

Why does it happen?

A function added for development or support ships to production without authentication. It often relies on the assumption that it is “only reachable from the internal network.”

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
// Added for the support teamapp.post("/maintenance/reset", resetDevice);

Fixed

ts
if (config.maintenanceEnabled) {  app.post(    "/maintenance/reset",    requireSession, requireRole("admin"), resetDevice  );}

How to prevent it

  1. 01Remove maintenance and debugging functions from production builds.
  2. 02If one must stay, protect it with an authorization check and a separate configuration flag.
  3. 03Never treat network location as a substitute for authentication.

CVEs in this class

2,751 records

  • Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    erlang · erlang\/otpApr 16, 2025

  • Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    langflow · langflowApr 7, 2025

  • On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    f5 · big-ip access policy managerMay 5, 2022

  • Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authenticatio

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    zohocorp · manageengine servicedesk plusSep 1, 2021

  • The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · airflowNov 10, 2020

  • Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    oracle · e-business suiteOct 18, 2022

  • SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    sap · solution managerMar 10, 2020

  • Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    splunk · splunkJun 10, 2026

  • Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).

    CriticalCVSS 9.8KEVWeaponizedEPSS 96%

    oracle · access managerJan 19, 2022

  • SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an

    CriticalCVSS 10.0KEVWeaponizedEPSS 95%

    sap · netweaver application server javaJul 14, 2020

  • PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

    CriticalCVSS 9.3KEVWeaponizedEPSS 100%

    paloaltonetworks · pan-osNov 18, 2024

  • WebPros cPanel and WHM Authentication Bypass via Login Flow

    CriticalCVSS 9.3KEVWeaponizedEPSS 99%

    cpanel · cpanelApr 29, 2026

  • A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fo

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    fortinet · fortimanagerOct 23, 2024

  • Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to un

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    zohocorp · manageengine servicedesk plusNov 29, 2021

  • ProjectSend Unauthenticated Configuration Modification

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    projectsend · projectsendNov 26, 2024

  • Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    vmware · vcenter serverApr 10, 2020

  • Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).

    CriticalCVSS 9.8KEVWeaponizedEPSS 89%

    oracle · identity managerOct 21, 2025

  • PAN-OS: Authentication Bypass in the Management Web Interface

    HighCVSS 8.8KEVWeaponizedEPSS 98%

    paloaltonetworks · pan-osFeb 12, 2025

  • Expedition: Missing Authentication Leads to Admin Account Takeover

    CriticalCVSS 9.3KEVWeaponizedEPSS 92%

    paloaltonetworks · expeditionJul 10, 2024

  • The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    mitel · micollabMar 10, 2022

  • upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    cyberpanel · cyberpanelOct 29, 2024

  • SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API

    CriticalCVSS 9.3KEVWeaponizedEPSS 88%

    smartertools · smartermailJan 23, 2026

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security).

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    oracle · weblogic serverOct 19, 2017

  • TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/a

    HighCVSS 7.5KEVWeaponizedEPSS 83%

    terra-master · terramaster operating systemFeb 7, 2023

  • Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.

    HighCVSS 7.5KEVWeaponizedEPSS 81%

    veeam · veeam backup \& replicationMar 10, 2023

All vulnerability classes