Weaknesses of type CWE-306

2,622 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-29061MEDIUMLack of Adequate BIOS AuthenticationEPSS 0.4%CVE-2023-7325CRITICALMingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRFEPSS 0.4%CVE-2026-82276MEDIUMStarRocks Frontend REST Handlers Bypass the Base Class Authentication GateEPSS 0.4%CVE-2026-54068MEDIUMSiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIconEPSS 0.4%CVE-2026-86506MEDIUMIn JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling dataEPSS 0.4%CVE-2025-3474MEDIUMPanels - Critical - Access bypass - SA-CONTRIB-2025-033EPSS 0.4%CVE-2024-47912HIGHA vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an uEPSS 0.4%CVE-2026-0283MEDIUMPAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)EPSS 0.4%CVE-2026-76447MEDIUMCisco Identity Services Engine Certificate Reload VulnerabilityEPSS 0.4%CVE-2026-56677HIGH9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test EndpointEPSS 0.4%CVE-2025-14349HIGHBusiness Logic Error in Universal Software's FlexCity/KioskEPSS 0.4%CVE-2026-48692HIGHFastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initializEPSS 0.4%CVE-2026-50082MEDIUMAqara Developer Portal insecure authentication tokenEPSS 0.4%CVE-2026-34949MEDIUMCombodo iTop: Unauthenticated user can delete .readonly fileEPSS 0.4%CVE-2026-40856HIGHConfig disclosure in T-Mobile 5G Box IDU routersEPSS 0.4%CVE-2023-31227HIGHThe hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confiEPSS 0.4%CVE-2026-49471HIGHSerena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEEPSS 0.4%CVE-2026-60557MEDIUMVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2025-41689HIGHWiesemann & Theis: Motherbox 3 allows unauthenticated read-only DB accessEPSS 0.4%CVE-2025-3319HIGHIBM Spectrum Protect Server authentication bypassEPSS 0.4%