Weaknesses of type CWE-306

2,623 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-52551CRITICALProprietary protocol allows for unauthenticated file operationsEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%CVE-2025-52182HIGHThe Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.EPSS 0.3%CVE-2023-7328MEDIUMScreen SFT DAB 600/C <= 1.9.3 Unauthenticated Information DisclosureEPSS 0.3%CVE-2026-18111HIGHConcrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verificationEPSS 0.3%CVE-2026-76640HIGHUnitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning StackEPSS 0.3%CVE-2024-21824MEDIUMImproper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER IEPSS 0.3%CVE-2026-32291HIGHGL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial consoleEPSS 0.3%CVE-2025-20085HIGHA denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted EPSS 0.3%CVE-2026-60671HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). SupportEPSS 0.3%CVE-2026-44830HIGHEmpty API_TOKEN disables authentication on network-reachable HTTP/SSE transportEPSS 0.3%CVE-2026-60235HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.3%CVE-2024-49572HIGHA denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pEPSS 0.3%CVE-2025-42875MEDIUMMissing Authentication check in SAP NetWeaver Internet Communication FrameworkEPSS 0.3%CVE-2026-75754CRITICALMissing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center aEPSS 0.3%CVE-2025-51543CRITICALAn issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_pEPSS 0.3%CVE-2025-65007HIGHMissing Authentication for Critical Function in WODESYS WD-R608U routerEPSS 0.3%CVE-2026-82784MEDIUMMissing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may exEPSS 0.3%CVE-2026-87195HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-4382MEDIUMGrub2: grub allow access to encrypted device through cli once root device is unlocked via tpmEPSS 0.3%