Missing Authentication for Critical Function (CWE-306)
CWE-306 applies when a product performs no authentication at all for a function that needs a provable user identity or consumes significant resources. A common pattern is protecting one channel while a secondary channel, assumed private, accepts connections without checks.
About CWE-306
Exposed functionality gives an attacker the privilege level of that function. Depending on what is exposed, this ranges from reading or modifying sensitive data to reaching administrative features or executing code.
Mitigations
- +Divide the software into anonymous, normal, privileged and administrative areas, and require proven identity where needed through a centralized mechanism.
- +Identify every communication channel and protect each one, including channels assumed to be reachable only by authorized parties.
- +Use the authentication capabilities of the framework, operating system or environment instead of custom routines.
- +Apply custom authentication to every page or endpoint, since each can be requested directly.
- +Require strong authentication on cloud storage through the provider's access controls.
Detection
Manual analysis such as penetration testing and threat modeling is useful, especially for custom schemes. Automated static analysis can spot common authentication idioms but has limited effectiveness against custom designs.
CWE-306 Vulnerabilities
28 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-67277 | Kernel memory disclosure and denial of service in MikroTik RouterOS btest service | Mikrotik | 8.8 | 1.6% | KEV | 2026-09-05 |
| CVE-2026-59822 | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | BerriAI | 8.8 | 0.8% | KEV | 2026-07-08 |
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | TrueConf | 9.8 | 1.5% | KEV | 2026-08-19 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Microsoft | 5.3 | 1.0% | KEV | 2026-07-14 |
| CVE-2026-41940 | WebPros cPanel and WHM Authentication Bypass via Login Flow | WebPros | 9.8 | 98.5% | KEV | 2026-04-29 |
| CVE-2026-39987 | marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass | marimo-team | 9.3 | 37.9% | KEV | 2026-04-09 |
| CVE-2026-33017 | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint | langflow-ai | 9.3 | 24.8% | KEV | 2026-03-20 |
| CVE-2026-24423 | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API | SmarterTools | 9.3 | 88.2% | KEV | 2026-01-23 |
| CVE-2025-4008 | Arbitrary Command Injection in Smartbedded MeteoBridge | Smartbedded | 8.7 | 93.7% | KEV | 2025-05-21 |
| CVE-2025-32433 | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE | erlang | 10.0 | 98.8% | KEV | 2025-04-16 |
| CVE-2025-3248 | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code | langflow-ai | 9.8 | 100.0% | KEV | 2025-04-07 |
| CVE-2025-34028 | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal | Commvault | 9.3 | 97.6% | KEV | 2025-04-22 |
| CVE-2025-0108 | PAN-OS: Authentication Bypass in the Management Web Interface | Palo Alto Networks | 8.8 | 98.5% | KEV | 2025-02-12 |
| CVE-2024-11680 | ProjectSend Unauthenticated Configuration Modification | ProjectSend | 9.8 | 91.7% | KEV | 2024-11-26 |
| CVE-2024-0012 | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) | Palo Alto Networks | 9.3 | 99.9% | KEV | 2024-11-18 |
| CVE-2024-5910 | Expedition: Missing Authentication Leads to Admin Account Takeover | Palo Alto Networks | 9.3 | 91.7% | KEV | 2024-07-10 |
| CVE-2024-8956 | PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication | PTZOptics | 9.1 | 58.8% | KEV | 2024-09-17 |
| CVE-2024-47575 | Fortinet FortiManager Missing Authentication Vulnerability | Fortinet | 9.8 | 94.8% | KEV | 2024-10-23 |
| CVE-2023-36846 | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files | Juniper Networks | 5.3 | 93.5% | KEV | 2023-08-17 |
| CVE-2023-36847 | Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files | Juniper Networks | 5.3 | 83.5% | KEV | 2023-08-17 |
| CVE-2023-36851 | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files | Juniper Networks | 5.3 | 1.1% | KEV | 2023-09-26 |
| CVE-2023-27532 | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | - | 7.5 | 81.3% | KEV | 2023-03-10 |
| CVE-2022-1388 | F5 BIG-IP Missing Authentication Vulnerability | F5 | 9.8 | 100.0% | KEV | 2022-05-05 |
| CVE-2026-23744 | REC in MCPJam inspector due to HTTP Endpoint exposes | MCPJam | 9.8 | 67.5% | 2026-01-16 | |
| CVE-2026-21445 | Langflow Missing Authentication on Critical API Endpoints | langflow-ai | 8.8 | 33.3% | 2026-01-02 | |
| CVE-2026-22679 | Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint | Weaver Network Co., Ltd. | 9.8 | 20.4% | 2026-04-07 | |
| CVE-2026-22812 | OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution | anomalyco | 8.8 | 16.5% | 2026-01-12 | |
| CVE-2026-25137 | NixOs Odoo database and filestore publicly accessible with default odoo configuration | NixOS | 9.1 | 10.5% | 2026-02-02 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-306?→
CWE-306 is the weakness of exposing a critical function with no authentication check. Anyone who can reach the function can use it.
How does CWE-306 differ from CWE-287?→
CWE-306 is a Base entry for authentication that is entirely missing on a critical function. CWE-287 is the broader Class for authentication that is absent or insufficient, and MITRE lists CWE-306 as a suggested alternative to it.
How many exploited vulnerabilities are classified as CWE-306?→
This database lists 28 CVE records mapped to CWE-306 by their CVE Numbering Authority. 23 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-67277, CVE-2026-59822, CVE-2026-72529.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.