CVEbaza.plSłownik CWECWE-306
Common Weakness Enumeration

CWE-306

Missing Authentication for Critical Function

Kategoria: BaseCVE: 3441
Opis

Produkt nie przeprowadza uwierzytelniania dla funkcjonalności, która wymaga potwierdzenia tożsamości użytkownika lub zużywa znaczną ilość zasobów. Ta luka w zabezpieczeniach pozwala nieuprawnionym użytkownikom na dostęp do funkcji, które powinny być ograniczone tylko dla autentycznych użytkowników.

Description (EN)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Podatności CVE z CWE-306 (3441)
10.0
CVSS
CRITICAL
CVE-2026-75754

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.

pub. 2026-09-04
10.0
CVSS
CRITICAL
CVE-2026-70352

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

pub. 2026-09-03
10.0
CVSS
CRITICAL
CVE-2026-81735

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and @agent-infra/mcp-server-filesystem entry points call startSseAndStreamableHttpMcpServer with a host and port alone and pass no middleware, so neither server required a credential. The commands server exposes a run_command tool that hands its caller-supplied command string to promisify(child_process.exec), so any unauthenticated client able to reach the port could run arbitrary commands as the user running the server, and the filesystem server exposed its file read and write tools on the same terms. The listen default became 127.0.0.1 in commit c2ad42e3eb9b27830db41a3e6f51ca7179d9b168; the package version stayed at 1.2.4 across that change, so the boundary is the commit rather than a release.

pub. 2026-08-27
10.0
CVSS
CRITICAL
CVE-2026-65956

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator authorization. Because reading, creating, and updating the global SSO configuration is not restricted to administrators, an unauthorized or low-privileged user can inspect or alter the authentication configuration, which under certain conditions can lead to account takeover or privilege escalation. The SSO connectivity-test function can additionally be abused as a server-side request forgery primitive, and the user list API returns user objects without consistently clearing authentication-related fields. This issue is fixed in version 2.0.0.

pub. 2026-08-26
10.0
CVSS
CRITICAL
CVE-2026-20357

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.

pub. 2026-08-19
10.0
CVSS
CRITICAL
CVE-2026-58115

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

pub. 2026-08-11
10.0
CVSS
CRITICAL
CVE-2026-63508

Podatność w Microsoft Planetary Computer Pro umożliwia nieuwierzytelnionemu atakującemu eskalację uprawnień przez sieć bez jakiejkolwiek interakcji użytkownika. Krytyczny wynik CVSS 10.0 oraz pełny zakres wpływu na poufność i integralność czynią tę lukę wyjątkowo poważną.

pub. 2026-08-07
10.0
CVSS
CRITICAL
CVE-2026-56163

Podatność w Microsoft Azure Kubernetes Service (AKS) umożliwia nieuwierzytelnionemu atakującemu zdalne podniesienie uprawnień poprzez sieć. Ocena CVSS 10.0 (Critical) wskazuje na maksymalne zagrożenie — brak wymagań co do uwierzytelnienia, interakcji użytkownika ani szczególnych warunków exploitacji.

pub. 2026-07-24
10.0
CVSS
CRITICAL
CVE-2026-64812

Podatność w JetBrains IntelliJ IDEA przed wersją 2026.2 umożliwia nieautoryzowane wstrzyknięcie danych wejściowych (input injection) w ramach sesji Remote Development. Ze względu na brak wymaganego uwierzytelnienia i maksymalny wynik CVSS 10.0, podatność stanowi krytyczne zagrożenie dla środowisk programistycznych.

pub. 2026-07-23
10.0
CVSS
CRITICAL
CVE-2026-60366

Podatność w komponencie Centralized Thirdparty Jars produktu Oracle Platform Security for Java umożliwia nieuwierzytelnionemu atakującemu zdalne przejęcie kontroli nad systemem poprzez sieć HTTP. Ocena CVSS 10.0 oznacza maksymalny poziom krytyczności.

pub. 2026-07-22
10.0
CVSS
CRITICAL
CVE-2026-47056

Oracle Data Integrator zawiera krytyczną podatność w komponencie Rest Service, umożliwiającą nieuwierzytelnionemu atakującemu zdalne przejęcie kontroli nad systemem. Podatność uzyskała maksymalny wynik CVSS 10.0, co czyni ją wyjątkowo niebezpieczną dla organizacji korzystających z tego produktu.

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-60217

Podatność w komponencie Core produktu Oracle Coherence (Oracle Fusion Middleware) pozwala nieuwierzytelnionemu atakującemu na zdalne przejęcie kontroli nad systemem przez sieć TCP. Otrzymała maksymalny wynik CVSS 10.0, co czyni ją podatnością najwyższego stopnia krytyczności.

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-60360

Krytyczna podatność w komponencie OUD Core produktu Oracle Unified Directory umożliwia nieuwierzytelnionemu atakującemu zdalne przejęcie kontroli nad systemem poprzez protokół LDAP. Ocena CVSS wynosi maksymalne 10.0, co czyni ją jedną z najpoważniejszych kategorii zagrożeń.

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-60365

Podatność w komponencie WebLogic Server Proxy Plug-In for Third-Party Web Servers produktu Oracle Fusion Middleware pozwala nieuwierzytelnionemu atakującemu na zdalny dostęp do krytycznych danych oraz ich modyfikację. Ocena CVSS 10.0 czyni tę lukę jedną z najpoważniejszych możliwych — nie wymaga uwierzytelnienia ani interakcji użytkownika.

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-60379

Podatność w komponencie Messaging Enabler produktu Oracle Service Delivery Platform (Oracle Fusion Middleware) umożliwia nieuwierzytelnionemu atakującemu zdalne przejęcie kontroli nad systemem przez sieć przy użyciu protokołu SOAP. Ocena CVSS 10.0 wskazuje na maksymalne ryzyko dla poufności, integralności i dostępności.

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-60389

Podatność w komponencie Messaging Enabler produktu Oracle Service Delivery Platform (Oracle Fusion Middleware) umożliwia nieuwierzytelnionemu atakującemu zdalne przejęcie pełnej kontroli nad systemem. Wysoki stopień zagrożenia wynika z braku wymagań co do uwierzytelnienia, prostoty exploitacji oraz możliwości wpływu na dodatkowe produkty (scope change).

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-60644

Podatność w komponencie Web Content Management produktu Oracle WebCenter Content (Oracle Fusion Middleware) umożliwia nieuprawnionemu atakującemu zdalne przejęcie kontroli nad systemem bez konieczności uwierzytelnienia. Ocena CVSS wynosi maksymalne 10.0, co oznacza najwyższy możliwy poziom zagrożenia.

pub. 2026-07-21
10.0
CVSS
CRITICAL
CVE-2026-46339

W aplikacji 9Router (wersje 0.4.30–0.4.36) middleware proxy.js nie wymuszał uwierzytelnienia dla ścieżek /api/cli-tools/* oraz /api/mcp/*, umożliwiając nieuwierzytelnionym atakującym rejestrację własnych wtyczek i wykonanie dowolnych poleceń systemowych. Podatność otrzymała maksymalny wynik CVSS 10.0, co czyni ją krytycznym zagrożeniem dla każdej instancji 9Router dostępnej z sieci.

pub. 2026-07-15
10.0
CVSS
CRITICAL
CVE-2026-62422

W JetBrains YouTrack wykryto krytyczną podatność umożliwiającą ominięcie uwierzytelniania poprzez bezpośredni dostęp do bazy danych, co prowadzi do uzyskania uprawnień administracyjnych. Brak wymogu uwierzytelnienia (CWE-306) w połączeniu z maksymalnym wynikiem CVSS 10.0 czyni tę podatność wyjątkowo niebezpieczną.

pub. 2026-07-14
10.0
CVSS
CRITICAL
CVE-2026-59726

Ruflo w wersjach przed 3.16.3 udostępniał endpointy MCP bridge bez jakiegokolwiek uwierzytelnienia, umożliwiając nieuwierzytelnionemu atakującemu zdalne wykonanie poleceń (RCE) w kontenerze. Podatność jest krytyczna — atakujący sieciowy bez żadnych uprawnień może przejąć kontrolę nad środowiskiem agenta.

pub. 2026-07-09
Pokazano 20 z 3441 podatności
Informacje
ID: CWE-306
Typ: Base
Podatności: 3441
MITRE CWE ↗
← Słownik CWE