Cwe-306 - Missing Authentication For Critical Function - Cwe

Threat entity extracted from intelligence sources

Frequency
22
occurrences
First Seen
April 24, 2026
Last Seen
September 8, 2026

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-76578 — access.redhat.com · September 8, 2026
  • 1 — github.com · September 7, 2026
  • Calix GigaSpire Flaw Lets Strangers Control Your Home Firewall: No Patch — Techtimes · August 25, 2026
  • New Report from Rapid7 Labs: Why Q2 2026 signals the end of traditional patch cycles — Rapid7 · August 18, 2026
  • CVE-2026-49827 - WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) Latest High/Critical Vulnerabilitiy Feed / 10h CVE ID : CVE-2026-49827 Published : Aug. 13, 2026, 1:19 p.m. 16 minutes ago Description : WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu — cvefeed.io · August 14, 2026
  • CVE 2026 0283 — security.paloaltonetworks.com · July 10, 2026
  • JVN#40604023 prior disclosure — jvn.jp · July 5, 2026
  • JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Vulnerabilities — Gbhackers · July 2, 2026

CVSS v3.1 Breakdown