Weaknesses of type CWE-306

2,624 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-0942MEDIUMRede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.5 - Missing Authorization to Unauthenticated Rede Order Logs DeletionEPSS 0.3%CVE-2026-100192MEDIUMX-SpringBoot through 6.0 Credential Exposure via Unauthenticated EndpointEPSS 0.3%CVE-2026-73222HIGHClaude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)EPSS 0.3%CVE-2025-12476CRITICALResource Lacking AuthNEPSS 0.3%CVE-2024-34268HIGHEQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth EPSS 0.3%CVE-2018-19636HIGHLocal root exploit via inclusion of attacker controlled shell scriptEPSS 0.3%CVE-2023-46096MEDIUMA vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authentEPSS 0.3%CVE-2025-8627HIGHUnauthenticated Protocol Commands on TP-Link KP303EPSS 0.3%CVE-2025-11771MEDIUMCryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.7 - Missing Authentication to Unauthenticated Presale UpdateEPSS 0.3%CVE-2025-6226MEDIUMIDOR in CreatePost API allows for timeboxed message disclosureEPSS 0.3%CVE-2025-60856MEDIUMReolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical accEPSS 0.3%CVE-2020-25697—A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker tEPSS 0.3%CVE-2026-71203MEDIUMchangedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI SchemaEPSS 0.3%CVE-2025-23194MEDIUMMissing Authentication check in SAP NetWeaver Enterprise Portal (OBN component)EPSS 0.3%CVE-2026-12989HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.3%CVE-2026-8335HIGHMissing authentication in Aix-DBEPSS 0.3%CVE-2025-32782MEDIUMAsh Authentication email link auto-click account confirmation vulnerabilityEPSS 0.3%CVE-2026-5777HIGHSecurity Misconfiguration Vulnerability in Atom 3x ProjectorEPSS 0.3%CVE-2024-9919HIGHMissing Authentication Check in parisneo/lollms-webuiEPSS 0.3%CVE-2026-59804HIGHMidscene Bridge Server - Session Hijack via Unauthenticated WebSocketEPSS 0.3%