Weaknesses of type CWE-306

2,627 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-27169HIGHLack of authenticationEPSS 0.3%CVE-2026-11848HIGHIEI Integration Corp| iRM-IEI Remote Management - Missing AuthenticationEPSS 0.3%CVE-2026-11539MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-55070MEDIUMLack of MFA enforcement in WebSocket connectionsEPSS 0.3%CVE-2026-10283MEDIUMBottelet DaybydayCRM Setting missing authenticationEPSS 0.3%CVE-2024-26519CRITICALAn issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to theEPSS 0.3%CVE-2026-44649CRITICALSillyTavern: Authentication Bypass via SSO Header InjectionEPSS 0.3%CVE-2025-3498CRITICALUnauthenticated modification of Radiflow iSAP Smart Collector configurationEPSS 0.3%CVE-2025-63896HIGHAn issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject EPSS 0.3%CVE-2025-62607MEDIUMNautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URLEPSS 0.3%CVE-2026-46999HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). SupportEPSS 0.3%CVE-2026-31944HIGHLibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect linkEPSS 0.3%CVE-2020-26192HIGHDell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CEPSS 0.3%CVE-2026-60705HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2024-10649MEDIUMUnauthenticated File Upload in wandb/openuiEPSS 0.3%CVE-2020-3335MEDIUMCisco Application Services Engine Software Authorization VulnerabilityEPSS 0.3%CVE-2025-10772MEDIUMhuggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authenticationEPSS 0.3%CVE-2026-50136HIGHBudibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialsEPSS 0.3%CVE-2026-28485HIGHOpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP EndpointsEPSS 0.3%CVE-2026-47038LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0EPSS 0.3%