Weaknesses of type CWE-306

2,623 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-46935HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-60769HIGHVulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-47858HIGHlive information startup mode is vulnerable for remote code executionEPSS 0.3%CVE-2026-1410MEDIUMBeetel 777VR1 UART missing authenticationEPSS 0.3%CVE-2026-16876CRITICALAn authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbEPSS 0.3%CVE-2026-34288MEDIUMVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that iEPSS 0.3%CVE-2026-33070LOWFileRise has Unauthenticated Share Link DeletionEPSS 0.3%CVE-2026-34289MEDIUMVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that iEPSS 0.3%CVE-2026-89034HIGHTCH QRing R20_B006 Unauthenticated BLE AccessEPSS 0.3%CVE-2026-53649CRITICALJoro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEEPSS 0.3%CVE-2026-26048HIGHJinan USR IOT Technology Limited (PUSR) USR-W610 Missing Authentication for Critical FunctionEPSS 0.3%CVE-2024-48950HIGHAn issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attacEPSS 0.3%CVE-2021-20262—A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to takeEPSS 0.3%CVE-2025-71409HIGHNo Authentication for Very High Frequency Data Link messages used in CPDLCEPSS 0.3%CVE-2025-56562HIGHAn incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC aEPSS 0.3%CVE-2026-3527MEDIUMAJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022EPSS 0.3%CVE-2026-73245MEDIUMKestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authEPSS 0.3%CVE-2026-36603HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, incluEPSS 0.3%CVE-2026-52480MEDIUMAn issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd serviceEPSS 0.3%CVE-2025-25736MEDIUMKapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pEPSS 0.3%