Weaknesses of type CWE-306

2,624 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-72542MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-22924HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthentiEPSS 0.3%CVE-2025-42926MEDIUMMissing Authentication check in SAP NetWeaver Application Server JavaEPSS 0.3%CVE-2026-60623HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.3%CVE-2026-72541MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-6673MEDIUMMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installEPSS 0.3%CVE-2024-51362MEDIUMThe LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed thEPSS 0.3%CVE-2026-26160HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62777HIGHWindows License Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50512HIGHMicrosoft PC Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50333HIGHWindows Spaceport.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-32326MEDIUMSHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the adminiEPSS 0.3%CVE-2026-61367HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69528HIGHWindows Shell Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61356HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26159HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61364HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61365HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-42976HIGHRemote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-11848HIGHIEI Integration Corp| iRM-IEI Remote Management - Missing AuthenticationEPSS 0.3%