Weaknesses of type CWE-306

2,622 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-83334HIGHVulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versionsEPSS 0.4%CVE-2025-63435MEDIUMXtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible foEPSS 0.4%CVE-2025-8754HIGHABB AbilityTM zenon Remote Transport VulnerabilityEPSS 0.4%CVE-2026-68578HIGHArcadeDB before 26.7.3 Authentication Bypass via MCP TransportEPSS 0.4%CVE-2026-59715LOWOpen WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)EPSS 0.4%CVE-2026-57495HIGHAgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)EPSS 0.4%CVE-2026-47019HIGHVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected EPSS 0.4%CVE-2026-60653HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2024-43272MEDIUMWordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Unpublished Campaign Viewer vulnerabilityEPSS 0.4%CVE-2026-19441MEDIUMUnauthenticated API Allows Analytics Data Manipulation in IKAS Technology's RushEPSS 0.4%CVE-2026-70805HIGHVulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versiEPSS 0.4%CVE-2024-7079MEDIUMOpenshift-console: unauthenticated installation of helm chartsEPSS 0.4%CVE-2023-30612MEDIUMMalicious HTTP requests could close arbitrary opening file descriptors in cloud-hypervisorEPSS 0.4%CVE-2024-9430MEDIUMGet Quote For Woocommerce – Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV DownloadEPSS 0.4%CVE-2026-5267HIGHUnauthenticated Event Stream Exposure of Session Tokens in Navigator NCSEPSS 0.4%CVE-2026-19908HIGHPAX Technology Q80 XCB Daemon Missing Authentication VulnerabilityEPSS 0.4%CVE-2018-25241HIGHVPN Browser+ 1.1.0.0 Denial of ServiceEPSS 0.4%CVE-2026-81032CRITICALNebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime ConfigurationEPSS 0.4%CVE-2026-49217HIGHMailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictionsEPSS 0.4%CVE-2026-83305HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%