CWE-306: Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Last updated
Overview
CWE-306 (Missing Authentication for Critical Function) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
1,395 recorded CVEs are caused by CWE-306 (Missing Authentication for Critical Function), including 39 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 347 new CWE-306 CVEs have been recorded so far in 2026 (403 in 2025).