Weaknesses of type CWE-306

2,623 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-46912CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions thatEPSS 0.4%CVE-2026-87196HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-35274HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.4%CVE-2022-26394MEDIUMUnauthenticated network reconfiguration via TCP/UDPEPSS 0.4%CVE-2026-60586HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.4%CVE-2026-33715HIGHChamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer actionEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2025-7635HIGHCalix GigaCenter ONT - Unauthenticated TelnetEPSS 0.4%CVE-2026-6272HIGHA client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStreamEPSS 0.4%CVE-2025-13483HIGHMissing Authentication for Critical Function in SiRcom SMART Alert (SiSA)EPSS 0.4%CVE-2026-35584MEDIUMFreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and EnumerationEPSS 0.4%CVE-2021-47709HIGHCOMMAX Smart Home Ruvie CCTV Bridge DVR Service Config Write / DoSEPSS 0.4%CVE-2021-47710HIGHCOMMAX Smart Home Ruvie CCTV Bridge DVR Service RTSP Credentials DisclosureEPSS 0.4%CVE-2026-17635CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2020-5326MEDIUMAffected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage ReEPSS 0.3%CVE-2026-53714HIGHEnvoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceModeEPSS 0.3%CVE-2026-50227MEDIUMMQTT WebSocket Command Execution Vulnerability in NitroSenseEPSS 0.3%CVE-2026-80207MEDIUMAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Notification Create EndpointEPSS 0.3%CVE-2019-25738CRITICALWordPress Hybrid Composer 1.4.6 Unauthenticated Settings ChangeEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%