Weaknesses of type CWE-306

2,623 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-87195HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-4382MEDIUMGrub2: grub allow access to encrypted device through cli once root device is unlocked via tpmEPSS 0.3%CVE-2026-61135HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.3%CVE-2025-41090HIGHImproper Access Control in CCN-CERT microCLAUDIAEPSS 0.3%CVE-2024-41968MEDIUMWAGO: Docker Settings Manipulation in Multiple DevicesEPSS 0.3%CVE-2025-4560MEDIUMNetvision ISOinsight - Missing AuthenticationEPSS 0.3%CVE-2025-15346CRITICALwolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirementEPSS 0.3%CVE-2026-54246MEDIUMSkipper routesrv-no-auth: All routesrv API Endpoints Lack AuthenticationEPSS 0.3%CVE-2025-30126MEDIUMAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remoEPSS 0.3%CVE-2025-25068HIGHBypassing MFA Enforcement on Plugin EndpointsEPSS 0.3%CVE-2025-36757MEDIUMBypass of administrator login screen in SolaX CloudEPSS 0.3%CVE-2022-31022MEDIUMMissing Role Based Access Control for the REST handlers in bleve/http packageEPSS 0.3%CVE-2020-27225—In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web seEPSS 0.3%CVE-2025-11728MEDIUMOceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status UpdateEPSS 0.3%CVE-2026-83343HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.3%CVE-2026-19853MEDIUMCyberTutor|NewSiteServer (NSS) - Missing AuthenticationEPSS 0.3%CVE-2023-37325MEDIUMD-Link DAP-2622 DDP Set SSID List Missing Authentication VulnerabilityEPSS 0.3%CVE-2026-44413HIGHIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised accessEPSS 0.3%CVE-2026-46934HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-60497HIGHVulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported versiEPSS 0.3%