Weaknesses of type CWE-306

2,624 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-13030MEDIUMAll versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An EPSS 0.3%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2025-61778CRITICALAkka.Remote TLS did not properly implement certificate-based authenticationEPSS 0.3%CVE-2026-50451HIGHWindows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-42885MEDIUMMissing authentication in SAP HANA 2.0 (hdbrss)EPSS 0.3%CVE-2026-61267HIGHVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versEPSS 0.3%CVE-2023-31033MEDIUMCVEEPSS 0.3%CVE-2025-7031MEDIUMConfig Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086EPSS 0.3%CVE-2025-12349MEDIUMEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue TriggerEPSS 0.3%CVE-2026-69674MEDIUMWindows Modern Device Management (MDM) Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2024-27892HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).EPSS 0.3%CVE-2026-83991MEDIUMWindows Cloud Files Mini Filter Driver Tampering VulnerabilityEPSS 0.3%CVE-2026-69554MEDIUMMicrosoft Windows Search Component Tampering VulnerabilityEPSS 0.3%CVE-2026-73004MEDIUMWindows Autopilot Tampering VulnerabilityEPSS 0.3%CVE-2026-72964MEDIUMWindows Internet Connection Sharing (ICS) Tampering VulnerabilityEPSS 0.3%CVE-2026-69321MEDIUMWindows Power Dependency Coordinator Tampering VulnerabilityEPSS 0.3%CVE-2026-46997MEDIUMVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported vEPSS 0.3%CVE-2025-0257MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other servicesEPSS 0.3%CVE-2026-72542MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-60781HIGHVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.3%