Skip to main content

About CWE-306

Exposed functionality gives an attacker the privilege level of that function. Depending on what is exposed, this ranges from reading or modifying sensitive data to reaching administrative features or executing code.

MITRE name
Missing Authentication for Critical Function
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft

Mitigations

  • +Divide the software into anonymous, normal, privileged and administrative areas, and require proven identity where needed through a centralized mechanism.
  • +Identify every communication channel and protect each one, including channels assumed to be reachable only by authorized parties.
  • +Use the authentication capabilities of the framework, operating system or environment instead of custom routines.
  • +Apply custom authentication to every page or endpoint, since each can be requested directly.
  • +Require strong authentication on cloud storage through the provider's access controls.

Detection
Manual analysis such as penetration testing and threat modeling is useful, especially for custom schemes. Automated static analysis can spot common authentication idioms but has limited effectiveness against custom designs.

CWE-306 Vulnerabilities

28 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-67277
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
Mikrotik8.81.6%KEV2026-09-05
CVE-2026-59822
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
BerriAI8.80.8%KEV2026-07-08
CVE-2026-72529
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf9.81.5%KEV2026-08-19
CVE-2026-56164
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft5.31.0%KEV2026-07-14
CVE-2026-41940
WebPros cPanel and WHM Authentication Bypass via Login Flow
WebPros9.898.5%KEV2026-04-29
CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
marimo-team9.337.9%KEV2026-04-09
CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
langflow-ai9.324.8%KEV2026-03-20
CVE-2026-24423
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
SmarterTools9.388.2%KEV2026-01-23
CVE-2025-4008
Arbitrary Command Injection in Smartbedded MeteoBridge
Smartbedded8.793.7%KEV2025-05-21
CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
erlang10.098.8%KEV2025-04-16
CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
langflow-ai9.8100.0%KEV2025-04-07
CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
Commvault9.397.6%KEV2025-04-22
CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface
Palo Alto Networks8.898.5%KEV2025-02-12
CVE-2024-11680
ProjectSend Unauthenticated Configuration Modification
ProjectSend9.891.7%KEV2024-11-26
CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
Palo Alto Networks9.399.9%KEV2024-11-18
CVE-2024-5910
Expedition: Missing Authentication Leads to Admin Account Takeover
Palo Alto Networks9.391.7%KEV2024-07-10
CVE-2024-8956
PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication
PTZOptics9.158.8%KEV2024-09-17
CVE-2024-47575
Fortinet FortiManager Missing Authentication Vulnerability
Fortinet9.894.8%KEV2024-10-23
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Juniper Networks5.393.5%KEV2023-08-17
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Juniper Networks5.383.5%KEV2023-08-17
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Juniper Networks5.31.1%KEV2023-09-26
CVE-2023-27532
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
-7.581.3%KEV2023-03-10
CVE-2022-1388
F5 BIG-IP Missing Authentication Vulnerability
F59.8100.0%KEV2022-05-05
CVE-2026-23744
REC in MCPJam inspector due to HTTP Endpoint exposes
MCPJam9.867.5%2026-01-16
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
langflow-ai8.833.3%2026-01-02
CVE-2026-22679
Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
Weaver Network Co., Ltd.9.820.4%2026-04-07
CVE-2026-22812
OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
anomalyco8.816.5%2026-01-12
CVE-2026-25137
NixOs Odoo database and filestore publicly accessible with default odoo configuration
NixOS9.110.5%2026-02-02

Frequently Asked Questions

What is CWE-306?→

CWE-306 is the weakness of exposing a critical function with no authentication check. Anyone who can reach the function can use it.

How does CWE-306 differ from CWE-287?→

CWE-306 is a Base entry for authentication that is entirely missing on a critical function. CWE-287 is the broader Class for authentication that is absent or insufficient, and MITRE lists CWE-306 as a suggested alternative to it.

How many exploited vulnerabilities are classified as CWE-306?→

This database lists 28 CVE records mapped to CWE-306 by their CVE Numbering Authority. 23 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-67277, CVE-2026-59822, CVE-2026-72529.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.