Weaknesses of type CWE-306

2,622 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2018-25241HIGHVPN Browser+ 1.1.0.0 Denial of ServiceEPSS 0.4%CVE-2026-81032CRITICALNebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime ConfigurationEPSS 0.4%CVE-2026-83305HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%CVE-2026-49217HIGHMailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictionsEPSS 0.4%CVE-2024-3774MEDIUMaEnrich Technology a+HRD - Exposure of Sensitive DataEPSS 0.4%CVE-2025-11986MEDIUMCrypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication StateEPSS 0.4%CVE-2025-6792MEDIUMOne to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message InterceptionEPSS 0.4%CVE-2025-53789HIGHWindows StateRepository API Server file Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2018-25246HIGHWikipedia 12.0 Denial of Service via SearchEPSS 0.4%CVE-2026-86106HIGHSecurity Advisory 0179EPSS 0.4%CVE-2026-61590HIGHdjust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUGEPSS 0.4%CVE-2026-28352MEDIUMIndico missing access check in event series management APIEPSS 0.4%CVE-2024-13173MEDIUMHealth information leakage vulnerabilityEPSS 0.4%CVE-2024-13186MEDIUMMinigameCenter information leakage vulnerabilityEPSS 0.4%CVE-2026-47671MEDIUMNhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secretsEPSS 0.4%CVE-2024-13185MEDIUMMinigameCenter module information leakage vulnerabilityEPSS 0.4%CVE-2026-35274HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.4%CVE-2026-60810HIGHVulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). SupportedEPSS 0.4%CVE-2026-60652HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2026-87197HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%