CWE-306: Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Browse cwe in implementation system configuration operation with official CWE context and Glexia analysis.
Search And Filters
Showing 5 of 5 CWE records.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
The product has a component that relies on a generative AI/ML model configured with inference parameters that produce an unacceptably high rate of erroneous or unexpected outputs.