#Missing Authentication
All CosmicBytez Labs articles tagged #Missing Authentication, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-49364: Apache ActiveMQ Artemis Cluster Credential Exposure
A pre-auth flaw in Artemis cluster discovery lets network-adjacent attackers capture admin credentials during the connection handshake.
- Security
CVE-2026-57967: Apache ActiveMQ Artemis Session Hijack via CORE Protocol
Attackers can craft a CORE protocol SESSION_REATTACH packet to steal an existing Artemis session and its authenticated privileges.
- Security
CVE-2026-67593: Apache ActiveMQ Artemis Unauthenticated Queue Deletion
A crafted OpenWire RemoveSubscriptionInfo command lets unauthenticated attackers delete Artemis broker queues before login completes.
- Security
CVE-2026-14622: Missing Authentication in Restaurant Website PHP/MySQL AJAX Endpoint
A missing authentication vulnerability (CVSS 7.3) in the jairiidriss/restaurant-website-php-mysql project exposes the /admin/ajax_files endpoint to...
- Security
CVE-2026-6577: DjangoBlog Missing Authentication in OwnTracks logtracks Endpoint
A missing authentication vulnerability in liangliangyy DjangoBlog up to 2.1.0.0 allows unauthenticated remote attackers to access the logtracks endpoint...
- Security
CVE-2026-4312: DrangSoft GCB/FCB Audit Software Missing
A critical missing authentication flaw (CVSS 9.8) in DrangSoft's GCB/FCB Audit Software allows unauthenticated remote attackers to directly access...