Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-5947MEDIUMDeep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure VulnerabilityEPSS 2.4%CVE-2022-45378CRITICALApache SOAP allows unauthenticated users to potentially invoke arbitrary codeEPSS 2.4%CVE-2021-39233—Container-related datanode operations can be called without authorizationEPSS 2.4%CVE-2019-3917—The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on thEPSS 2.4%CVE-2024-37152MEDIUMUnauthenticated Access to sensitive settings in Argo CDEPSS 2.3%CVE-2025-59516HIGHWindows Storage VSP Driver Elevation of Privilege VulnerabilityEPSS 2.3%CVE-2017-12733—A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel InEPSS 2.3%CVE-2020-12017—GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web appEPSS 2.3%CVE-2021-1393CRITICALCisco Application Services Engine Unauthorized Access VulnerabilitiesEPSS 2.3%CVE-2022-45477CRITICALTelepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization EPSS 2.3%CVE-2020-7540—A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon QuantuEPSS 2.3%CVE-2014-125116CRITICALHybridAuth 2.0.9 - 2.2.2 Unauthenticated RCE via install.php Configuration InjectionEPSS 2.3%CVE-2019-5163MEDIUMAn exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream CiphEPSS 2.3%CVE-2019-1895CRITICALCisco Enterprise NFV Infrastructure Software VNC Authentication Bypass VulnerabilityEPSS 2.3%CVE-2018-4853—A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to porEPSS 2.3%CVE-2025-34089CRITICALRemote for Mac Unauthenticated Remote Code Execution via AppleScript InjectionEPSS 2.3%CVE-2022-4978CRITICALSteppschuh Remote Control Server 3.1.1.12 Unauthenticated RCEEPSS 2.3%CVE-2019-1631MEDIUMCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 2.2%CVE-2020-6769CRITICALMissing Authentication for Critical Function in Bosch Video Streaming GatewayEPSS 2.2%CVE-2020-3531CRITICALCisco IoT Field Network Director Unauthenticated REST API VulnerabilityEPSS 2.2%