Weaknesses of type CWE-306

2,624 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-48953HIGHAn issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proEPSS 0.3%CVE-2021-34983MEDIUMNETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-43881MEDIUMWWBN AVideo: Unauthenticated User Enumeration in `objects/users.json.php` via `isCompany` Parameter Flips `$ignoreAdmin = true` and Defeats Admin-Only Listing GuardEPSS 0.3%CVE-2026-0492HIGHPrivilege escalation vulnerability in SAP HANA databaseEPSS 0.3%CVE-2018-25140CRITICALFLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated Websocket Device ManipulationEPSS 0.3%CVE-2026-12199HIGHUnauthenticated Denial of Service in nltk.app.wordnet_appEPSS 0.3%CVE-2025-12477CRITICALServer Version DisclosureEPSS 0.3%CVE-2026-76439MEDIUMCisco Identity Services Engine Event Injection VulnerabilityEPSS 0.3%CVE-2022-48496—Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause maEPSS 0.3%CVE-2026-54367HIGHCentreStack < 17.2 Unauthenticated API Authorization BypassEPSS 0.3%CVE-2026-66098HIGHMira Hormone Monitor, Mira Android App Missing authentication for critical functionEPSS 0.3%CVE-2022-48494—Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause maEPSS 0.3%CVE-2025-61756HIGHVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.3%CVE-2025-56405HIGHAn issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP serviceEPSS 0.3%CVE-2025-62619MEDIUMMissing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrievEPSS 0.3%CVE-2025-54850HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.3%CVE-2025-54849HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.3%CVE-2026-88410HIGHThe graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the EPSS 0.3%CVE-2025-12049CRITICALMissing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may EPSS 0.3%CVE-2026-100192MEDIUMX-SpringBoot through 6.0 Credential Exposure via Unauthenticated EndpointEPSS 0.3%