Weaknesses of type CWE-306

2,619 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-7045MEDIUMCloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config ActionEPSS 0.4%CVE-2024-37767HIGHInsecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET reqEPSS 0.4%CVE-2017-20220HIGHServiio PRO 1.8 Unauthenticated Password Change via REST APIEPSS 0.4%CVE-2026-3558HIGHPhilips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-76701MEDIUMUnauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2026-44949HIGHUnauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhookEPSS 0.4%CVE-2025-61673HIGHKarapace is vulnerable to Authentication BypassEPSS 0.4%CVE-2022-41505MEDIUMAn access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UAREPSS 0.4%CVE-2026-83115HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versiEPSS 0.4%CVE-2024-22326MEDIUMIBM System Storage improper authenticationEPSS 0.4%CVE-2025-12348MEDIUMEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task ExecutionEPSS 0.4%CVE-2026-31846HIGHUnauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+EPSS 0.4%CVE-2023-45220HIGHThe Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol tEPSS 0.4%CVE-2025-20210HIGHCisco Catalyst Center Unprotected API EndpointEPSS 0.4%CVE-2024-58336HIGHAkuvox Smart Intercom S539 Unauthenticated Video Stream DisclosureEPSS 0.4%CVE-2024-53623HIGHIncorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.EPSS 0.4%CVE-2023-35874MEDIUMImproper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP PlatformEPSS 0.4%CVE-2026-60831HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions thaEPSS 0.4%CVE-2026-60742HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions thEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%