Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-73296CRITICALMicrosoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosureEPSS 2.9%CVE-2026-59801CRITICAL9Router 0.4.41 - Unauthenticated API Exposure via /api/providersEPSS 2.9%CVE-2020-12500CRITICALPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productsEPSS 2.9%CVE-2025-34112CRITICALRiverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCEEPSS 2.9%CVE-2026-9103CRITICALUnauthenticated Superuser Token Issuance via Auto-Login EndpointEPSS 2.8%CVE-2020-10921CRITICALThis vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen EPSS 2.8%CVE-2026-42796CRITICALArelle < 2.39.10 Unauthenticated RCE via /rest/configureEPSS 2.7%CVE-2019-10919—A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp couEPSS 2.7%CVE-2019-18339CRITICALA vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVEPSS 2.7%CVE-2018-18995—Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativEPSS 2.6%CVE-2019-10922—A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WEPSS 2.6%CVE-2018-0377—A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, EPSS 2.6%CVE-2018-0376—A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to accesEPSS 2.6%CVE-2018-0374—A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connecEPSS 2.6%CVE-2021-43832CRITICALImproper Access Control in spinnakerEPSS 2.6%CVE-2018-4854—A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to porEPSS 2.5%CVE-2025-0896CRITICALOrthanc Server Missing Authentication for Critical FunctionEPSS 2.5%CVE-2020-10272CRITICALRVD#2554: MiR ROS computational graph presents no authentication mechanismsEPSS 2.5%CVE-2026-41452CRITICALKrayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setupEPSS 2.5%CVE-2025-34121CRITICALIdera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCEEPSS 2.4%