On this page
CWE-306: Missing Authentication for Critical Function
Weakness Summary
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
- Canonical source: MITRE CWE-306 (opens in a new tab)
- Published Atomicorp CVE observations: 63
- Distinct affected products in those observations: 59
- Active Atomicorp rules associated with this weakness: 84
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2024-46506 | NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution | netalertx | Attack Blocked by Atomicorp | 392301 , 392648 |
| CVE-2025-34073 | Maltrail <=0.54 Username Parameter - Remote Command Execution | Maltrail | Attack Blocked by Atomicorp | 340014 , 344363 , 344370 |
| CVE-2026-81735 | UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi | UI-TARS-desktop | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2017-18001 | Trustwave SWG 11.8.0.27 - SSH Unauthorized Access | secure web gateway | Attack Blocked by Atomicorp | 330039 , 330791 , 340152 |
| CVE-2018-0127 | Cisco RV132W/RV134W Router - Information Disclosure | rv132w firmware | Attack Blocked by Atomicorp | 312863 , 390716 |
| CVE-2018-6223 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | Attack Blocked by Atomicorp | 333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704 |
| CVE-2019-17506 | D-Link DIR-868L/817LW - Information Disclosure | dir-868l b1 firmware | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2020-10148 | SolarWinds Orion API - Auth Bypass | orion platform | Attack Blocked by Atomicorp | 390709 |
| CVE-2020-12720 | vBulletin SQL Injection | vbulletin | Attack Blocked by Atomicorp | 340016 , 340017 , 340155 , 340157 , 340159 , 341155 , 341245 , 360147 , 360148 |
| CVE-2020-9480 | Apache Spark - Authentication Bypass | spark | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2021-20158 | Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change | tew-827dru firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2021-34621 | WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness | profilepress | Detected by Atomicorp | 377360 |
| CVE-2022-1388 | F5 BIG-IP iControl - REST Auth Bypass RCE | big-ip access policy manager | Attack Blocked by Atomicorp | 344361 , 392767 |
| CVE-2023-46747 | F5 BIG-IP - Unauthenticated RCE via AJP Smuggling | big-ip access policy manager | Attack Blocked by Atomicorp | 390626 , 392767 |
| CVE-2025-3248 | Langflow AI - Unauthenticated Remote Code Execution | langflow | Attack Blocked by Atomicorp | 340095 , 344360 , 344370 |
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE | peoplesoft enterprise peopletools | Detected by Atomicorp | 331032 |
| CVE-2026-45695 | Kopia Server 0.23.0 - Remote Code Execution | kopia | Attack Blocked by Atomicorp | 393655 |
| CVE-2026-47391 | PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool execution | PraisonAI | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-49819 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | UpSnap | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-49827 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) | WebErpMesv2 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | joro | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-25895 | FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Write | fuxa | Attack Blocked by Atomicorp | 340007 |
| CVE-2026-88062 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | OmniRoute | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2022-26833 | Open Automation Software OAS Platform V16.00.0121 - Missing Authentication | oas platform | Attack Blocked by Atomicorp | 390726 , 392647 |
| CVE-2018-25412 | Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php | deltasql | Attack Blocked by Atomicorp | 351000 |
| CVE-2021-47940 | WordPress Download From Files 1.48 Arbitrary File Upload | Download From Files | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-41940 | cPanel & WHM - Authentication Bypass via Session-File CRLF Injection | cpanel | Detected by Atomicorp | 377364 |
| CVE-2026-4810 | Google ADK-Python - Unauthenticated Builder Endpoint | adk-python | Attack Blocked by Atomicorp | 390726 , 392647 |
| CVE-2026-56782 | Gorse < 0.5.10 - Unauthenticated Database Dump | gorse | Attack Blocked by Atomicorp | 301007 |
| CVE-2026-67426 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | flyto-core | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-41179 | RClone RC - Command Injection | rclone | Attack Blocked by Atomicorp | 340014 , 344370 |
| CVE-2026-42796 | Arelle < 2.39.10 - Remote Code Execution | arelle | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2019-9880 | WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure | wpgraphql | Attack Blocked by Atomicorp | 344361 , 344363 |
| CVE-2020-36333 | ThemeGrill Demo Importer < 1.6.2 - Database Reset | themegrill demo importer | Attack Blocked by Atomicorp | 375357 |
| CVE-2026-86259 | OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | OpenMAIC | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022 |
| CVE-2018-7357 | ZTE ZXHN H168N - Improper Access Restrictions | zxhn h168n firmware | Attack Blocked by Atomicorp | 330791 , 334168 , 340152 |
| CVE-2019-25678 | C4G BLIS 3.4 SQL Injection via users_select.php | computing for good's basic laboratory information system | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-9082 | ThinkPHP < 3.2.4 - Remote Code Execution | thinkphp | Attack Blocked by Atomicorp | 344361 , 393753 |
| CVE-2026-41473 | CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints | cyberpanel | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-60009 | theia Arbitrary Code Execution Vulnerability | theia | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio) | claude-code-templates | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2023-54350 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated | Augmented Reality | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 , 393781 |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | OP5 Monitor | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-4008 | MeteoBridge <= 6.1 - Remote Code Execution | meteobridge vm | Attack Blocked by Atomicorp | 393655 |
| CVE-2026-63722 | ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php | ICEcoder | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-89250 | WWBN AVideo Unauthenticated File Read via getRecordedFile.php | AVideo | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-34160 | Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser | chamilo lms | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-56677 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | 9router | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-63429 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context | heyform | Attack Blocked by Atomicorp | 351000 |
| CVE-2021-39144 | XStream 1.4.18 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344363 |
| CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | serena | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | vite | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2021-25094 | Wordpress Tatsubuilder <= 3.3.11 - Remote Code Execution | tatsu | Attack Blocked by Atomicorp | 382238 |
| CVE-2017-10271 | Oracle WebLogic Server - Remote Command Execution | weblogic server | Attack Blocked by Atomicorp | 344362 , 344363 , 344364 , 344366 |
| CVE-2019-19822 | TOTOLINK/Realtek Routers - Information Disclosure | a3002ru firmware | Attack Blocked by Atomicorp | 390716 |
| CVE-2020-10973 | WAVLINK - Access Control | wn530hg4 firmware | Attack Blocked by Atomicorp | 390716 |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | peoplesoft enterprise | Attack Blocked by Atomicorp | 340165 , 344360 , 344365 , 347009 |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | theia | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-33715 | Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action | chamilo lms | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-46555 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | whatsapp mcp server | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-65012 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder | InvokeAI | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2021-20150 | Trendnet AC2600 TEW-827DRU - Credentials Disclosure | tew-827dru firmware | Attack Blocked by Atomicorp | 392301 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 301007 | Active | disruptive (deny) |
| 312863 | Active | disruptive (deny) |
| 330039 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 331032 | Active | non-disruptive (pass) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 334168 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337210 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340155 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340159 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341155 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344382 | Active | disruptive (deny) |
| 344385 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 351000 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 375357 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 377364 | Active | non-disruptive (pass) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 382238 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390585 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390626 | Active | disruptive (deny) |
| 390704 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390716 | Active | disruptive (deny) |
| 390719 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 392767 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 393753 | Active | disruptive (deny) |
| 393781 | Active | disruptive (deny) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-12 (opens in a new tab) , CAPEC-166 (opens in a new tab) , CAPEC-216 (opens in a new tab) , CAPEC-36 (opens in a new tab) , CAPEC-62 (opens in a new tab)