Weaknesses of type CWE-306

2,619 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-35514MEDIUMUnauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions in ChartbrewEPSS 0.4%CVE-2024-6406HIGHSensetive Data Exposure in Yordam Information Technology's Mobile Library ApplicationEPSS 0.4%CVE-2025-59345HIGHDragonfly did not enable authentication for some Manager’s endpointsEPSS 0.4%CVE-2025-41716MEDIUMUnauthenticated User Enumeration via Missing AuthenticationEPSS 0.4%CVE-2025-43983CRITICALKuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_proceEPSS 0.4%CVE-2024-41791MEDIUMA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not autheEPSS 0.4%CVE-2026-97231MEDIUMvolotat Anagnorisis Socket.IO Connect app.py missing authenticationEPSS 0.4%CVE-2026-25751CRITICALFUXA Unauthenticated Exposure of Plaintext Database CredentialsEPSS 0.4%CVE-2026-54036MEDIUMLibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP VerificationEPSS 0.4%CVE-2024-40091MEDIUMVilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve lEPSS 0.4%CVE-2025-54864MEDIUMHydra missing authentication when triggering evaluations through GitHub and Gitea pluginsEPSS 0.4%CVE-2026-44320HIGHfree5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing pathEPSS 0.4%CVE-2023-44116—Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may caEPSS 0.4%CVE-2024-0336CRITICALImproper Access Control in EMTA Grups PDKSEPSS 0.4%CVE-2026-89027MEDIUMminiOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication DowngradeEPSS 0.4%CVE-2026-0842MEDIUMFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authenticationEPSS 0.4%CVE-2026-13125HIGHGeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerabilityEPSS 0.4%CVE-2026-17057MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]EPSS 0.4%CVE-2023-28761MEDIUMMissing Authentication check in SAP NetWeaver Enterprise PortalEPSS 0.4%CVE-2026-60255HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%