On this page

CWE-306: Missing Authentication for Critical Function

Weakness Summary

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

  • Canonical source: MITRE CWE-306 (opens in a new tab)
  • Published Atomicorp CVE observations: 63
  • Distinct affected products in those observations: 59
  • Active Atomicorp rules associated with this weakness: 84

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2024-46506NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code ExecutionnetalertxAttack Blocked by Atomicorp392301 , 392648
CVE-2025-34073Maltrail <=0.54 Username Parameter - Remote Command ExecutionMaltrailAttack Blocked by Atomicorp340014 , 344363 , 344370
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktopAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2017-18001Trustwave SWG 11.8.0.27 - SSH Unauthorized Accesssecure web gatewayAttack Blocked by Atomicorp330039 , 330791 , 340152
CVE-2018-0127Cisco RV132W/RV134W Router - Information Disclosurerv132w firmwareAttack Blocked by Atomicorp312863 , 390716
CVE-2018-6223Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gatewayAttack Blocked by Atomicorp333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2019-17506D-Link DIR-868L/817LW - Information Disclosuredir-868l b1 firmwareAttack Blocked by Atomicorp330791 , 340152
CVE-2020-10148SolarWinds Orion API - Auth Bypassorion platformAttack Blocked by Atomicorp390709
CVE-2020-12720vBulletin SQL InjectionvbulletinAttack Blocked by Atomicorp340016 , 340017 , 340155 , 340157 , 340159 , 341155 , 341245 , 360147 , 360148
CVE-2020-9480Apache Spark - Authentication BypasssparkAttack Blocked by Atomicorp340162 , 340163
CVE-2021-20158Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Changetew-827dru firmwareAttack Blocked by Atomicorp392301
CVE-2021-34621WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation WeaknessprofilepressDetected by Atomicorp377360
CVE-2022-1388F5 BIG-IP iControl - REST Auth Bypass RCEbig-ip access policy managerAttack Blocked by Atomicorp344361 , 392767
CVE-2023-46747F5 BIG-IP - Unauthenticated RCE via AJP Smugglingbig-ip access policy managerAttack Blocked by Atomicorp390626 , 392767
CVE-2025-3248Langflow AI - Unauthenticated Remote Code ExecutionlangflowAttack Blocked by Atomicorp340095 , 344360 , 344370
CVE-2026-35273Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCEpeoplesoft enterprise peopletoolsDetected by Atomicorp331032
CVE-2026-45695Kopia Server 0.23.0 - Remote Code ExecutionkopiaAttack Blocked by Atomicorp393655
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool executionPraisonAIAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnapAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-49827WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)WebErpMesv2Attack Blocked by Atomicorp351000
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoroAttack Blocked by Atomicorp340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-25895FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritefuxaAttack Blocked by Atomicorp340007
CVE-2026-88062OmniRoute ACP Custom-Agent Remote Code Execution (RCE)OmniRouteAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2022-26833Open Automation Software OAS Platform V16.00.0121 - Missing Authenticationoas platformAttack Blocked by Atomicorp390726 , 392647
CVE-2018-25412Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.phpdeltasqlAttack Blocked by Atomicorp351000
CVE-2021-47940WordPress Download From Files 1.48 Arbitrary File UploadDownload From FilesAttack Blocked by Atomicorp351000
CVE-2026-41940cPanel & WHM - Authentication Bypass via Session-File CRLF InjectioncpanelDetected by Atomicorp377364
CVE-2026-4810Google ADK-Python - Unauthenticated Builder Endpointadk-pythonAttack Blocked by Atomicorp390726 , 392647
CVE-2026-56782Gorse < 0.5.10 - Unauthenticated Database DumpgorseAttack Blocked by Atomicorp301007
CVE-2026-67426Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationflyto-coreAttack Blocked by Atomicorp337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-41179RClone RC - Command InjectionrcloneAttack Blocked by Atomicorp340014 , 344370
CVE-2026-42796Arelle < 2.39.10 - Remote Code ExecutionarelleAttack Blocked by Atomicorp340162 , 340163
CVE-2019-9880WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information DisclosurewpgraphqlAttack Blocked by Atomicorp344361 , 344363
CVE-2020-36333ThemeGrill Demo Importer < 1.6.2 - Database Resetthemegrill demo importerAttack Blocked by Atomicorp375357
CVE-2026-86259OpenMAIC before 1.0.1 SSRF via Environment-Gated URL ValidationOpenMAICAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022
CVE-2018-7357ZTE ZXHN H168N - Improper Access Restrictionszxhn h168n firmwareAttack Blocked by Atomicorp330791 , 334168 , 340152
CVE-2019-25678C4G BLIS 3.4 SQL Injection via users_select.phpcomputing for good&#x27;s basic laboratory information systemAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-9082ThinkPHP < 3.2.4 - Remote Code ExecutionthinkphpAttack Blocked by Atomicorp344361 , 393753
CVE-2026-41473CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner EndpointscyberpanelAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-60009theia Arbitrary Code Execution VulnerabilitytheiaAttack Blocked by Atomicorp351000
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templatesAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedAugmented RealityAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 , 393781
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 MonitorAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-4008MeteoBridge <= 6.1 - Remote Code Executionmeteobridge vmAttack Blocked by Atomicorp393655
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoderAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-89250WWBN AVideo Unauthenticated File Read via getRecordedFile.phpAVideoAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata serchamilo lmsAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-566779Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint9routerAttack Blocked by Atomicorp337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-63429HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextheyformAttack Blocked by Atomicorp351000
CVE-2021-39144XStream 1.4.18 - Remote Code ExecutionxstreamAttack Blocked by Atomicorp344363
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserenaAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketviteAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2021-25094Wordpress Tatsubuilder <= 3.3.11 - Remote Code ExecutiontatsuAttack Blocked by Atomicorp382238
CVE-2017-10271Oracle WebLogic Server - Remote Command Executionweblogic serverAttack Blocked by Atomicorp344362 , 344363 , 344364 , 344366
CVE-2019-19822TOTOLINK/Realtek Routers - Information Disclosurea3002ru firmwareAttack Blocked by Atomicorp390716
CVE-2020-10973WAVLINK - Access Controlwn530hg4 firmwareAttack Blocked by Atomicorp390716
CVE-2023-22047Oracle Peoplesoft - Unauthenticated File Readpeoplesoft enterpriseAttack Blocked by Atomicorp340165 , 344360 , 344365 , 347009
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor VulnerabilitytheiaAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer actionchamilo lmsAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-46555WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationwhatsapp mcp serverAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassfootprints itsmAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderInvokeAIAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2021-20150Trendnet AC2600 TEW-827DRU - Credentials Disclosuretew-827dru firmwareAttack Blocked by Atomicorp392301

Associated Atomicorp WAF Rules

RuleStatusBehavior
301007Activedisruptive (deny)
312863Activedisruptive (deny)
330039Activedisruptive (deny)
330791Activedisruptive (deny)
331032Activenon-disruptive (pass)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
334168Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
337209Activedisruptive (deny)
337210Activedisruptive (deny)
337211Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340095Activedisruptive (deny)
340144Activedisruptive (deny)
340145Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340155Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340159Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341145Activedisruptive (deny)
341155Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344362Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
344382Activedisruptive (deny)
344385Activedisruptive (deny)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
351000Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
375357Activedisruptive (deny)
377360Activenon-disruptive (pass)
377364Activenon-disruptive (pass)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
382238Activedisruptive (deny)
390572Activedisruptive (deny)
390585Activedisruptive (deny)
390613Activedisruptive (deny)
390614Activedisruptive (deny)
390626Activedisruptive (deny)
390704Activedisruptive (deny)
390709Activedisruptive (deny)
390716Activedisruptive (deny)
390719Activedisruptive (deny)
390722Activedisruptive (deny)
390726Activedisruptive (deny)
390904Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
392767Activedisruptive (deny)
393655Activedisruptive (deny)
393753Activedisruptive (deny)
393781Activedisruptive (deny)
398008Activenon-disruptive (pass)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-12 (opens in a new tab) , CAPEC-166 (opens in a new tab) , CAPEC-216 (opens in a new tab) , CAPEC-36 (opens in a new tab) , CAPEC-62 (opens in a new tab)