Weaknesses of type CWE-306

2,622 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-41689HIGHWiesemann & Theis: Motherbox 3 allows unauthenticated read-only DB accessEPSS 0.4%CVE-2026-54365HIGHCentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dllEPSS 0.4%CVE-2026-71566CRITICALKubeVirt backend is not authenticatedEPSS 0.4%CVE-2025-59780HIGHGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-61239CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supporEPSS 0.4%CVE-2026-8694MEDIUMImproper access control on the API documentation endpoint in PowerShell UniversalEPSS 0.4%CVE-2026-2675MEDIUMMissing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.EPSS 0.4%CVE-2025-14300HIGHUnauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425EPSS 0.4%CVE-2025-14294MEDIUMRazorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order ModificationEPSS 0.4%CVE-2025-47850MEDIUMIn JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloningEPSS 0.4%CVE-2026-77977HIGHEbyte NA111-M Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-10711HIGHRCE in Akınsoft's CafePlusEPSS 0.4%CVE-2024-40087CRITICALVilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 alEPSS 0.4%CVE-2025-7970HIGHRockwell Automation FactoryTalk Activation Manager Lack of Encryption VulnerabilityEPSS 0.4%CVE-2026-49195HIGHPredator Connect W6x: unauthenticated Debug ServiceEPSS 0.4%CVE-2025-48733HIGHDuraComm DP-10iN-100-MU Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-7187HIGHImproper Authentication in Universal Sotware's UKBSEPSS 0.4%CVE-2026-81664MEDIUMOpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /system/telemetry RouteEPSS 0.4%CVE-2025-11672MEDIUMEBM Technologies|Uniweb/SoliPACS WebServer - Missing AuthenticationEPSS 0.4%CVE-2025-11671MEDIUMEBM Technologies|Uniweb/SoliPACS WebServer - Missing AuthenticationEPSS 0.4%