A missing authentication vulnerability was identified in the-momentum open-wearables up to version 0.6.2. The flaw exists in the redeem_invitation_code function within the file backend/app/api/routes/v1/user_invitation_code.py at the Public Invitation-Code Redemption Endpoint. By manipulating the 'code' argument, an unauthenticated remote attacker can exploit this endpoint without proper authentication checks. The vulnerability allows remote exploitation, potentially enabling unauthorized access or abuse of the invitation system. The project was disclosed the issue via an issue report but has not responded or patched the vulnerability as of the article date. No CVSSv3 score or patch is currently available. The lack of vendor response increases the risk of exploitation in the wild.