Skip to content
Threat Feed

Tag

Missing-Authentication

6 briefs RSS
high advisory

CVE-2026-7187: Missing Authentication Vulnerability in Universal Software Inc. UKBS

A missing authentication for critical function vulnerability, tracked as CVE-2026-7187, in Universal Software Inc.'s UKBS product allows attackers to bypass authentication and access functionality not properly constrained by Access Control Lists (ACLs), leading to unauthorized operations.

UKBS vulnerability missing-authentication CVE-2026-7187
1t 1c
high advisory

Unauthenticated API Key Use in NetLicensing-MCP HTTP Mode

An unauthenticated vulnerability exists in netlicensing-mcp (version 0.1.5 and earlier) when operating in HTTP transport mode, where the ApiKeyMiddleware fails to enforce authentication for requests lacking a client API key, causing the application to fall back to the server's NETLICENSING_API_KEY environment variable for upstream calls, allowing an unauthenticated network attacker to invoke any MCP tool under the server operator's identity and account quota.

netlicensing-mcp web-vulnerability missing-authentication api-security supply-chain http
5t
high advisory

TinyIce Unauthenticated WebRTC Stream Injection Vulnerability

TinyIce versions 0.8.95 through 2.4.1 are vulnerable to unauthenticated stream injection due to a missing authentication check on the WebRTC ingest endpoint (/webrtc/source-offer), allowing a network attacker to hijack broadcasts by publishing arbitrary audio/video to a target mount, replacing the legitimate source's content; patched in version 2.5.0 (CVE-2026-45327).

tinyice webrtc stream-injection missing-authentication
2r 1t
high threat

FlowiseAI OpenAI Assistants Vector Store Missing Authentication

FlowiseAI versions 3.1.1 and earlier are vulnerable to a privilege escalation due to missing authentication and permission checks on the OpenAI Assistants Vector Store CRUD endpoints, allowing any authenticated user to create, modify, upload files to, and delete vector stores and files, regardless of their assigned permissions.

flowise privilege-escalation missing-authentication crud
2r 1t
critical advisory

Simopro WinMatrix Agent Missing Authentication Vulnerability (CVE-2026-6348)

The WinMatrix agent by Simopro Technology suffers from a missing authentication vulnerability (CVE-2026-6348), enabling local authenticated attackers to execute arbitrary code with SYSTEM privileges on the local machine and all hosts within the agent's environment.

CVE-2026-6348 missing-authentication privilege-escalation windows
2r 2t 1c
high advisory

Galaxy Software Services Vitals ESP Missing Authentication Vulnerability (CVE-2026-4640)

Vitals ESP developed by Galaxy Software Services suffers from a missing authentication vulnerability (CVE-2026-4640), enabling unauthenticated remote attackers to execute functions and obtain sensitive information.

cve-2026-4640 missing-authentication vitals-esp
2r 1t