Skip to content

security_identifier

CWE-306

CWE-306 is a software weakness classification for systems that let users access sensitive functions or resources without requiring authentication first.

Known aliases

  • CWE-306
  • missing-authentication flaws
  • Missing Authentication for Critical Function

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60