Weaknesses of type CWE-306

2,627 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-47038LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0EPSS 0.3%CVE-2026-76444MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-36457MEDIUMSymantec Privileged Access Manager Authentication Bypass vulnerabilityEPSS 0.3%CVE-2023-2827HIGHMissing Authentication in SAP Plant Connectivity and Production Connector for SAP DigitalEPSS 0.3%CVE-2025-13779HIGHConfiguration Data SpillEPSS 0.3%CVE-2025-6920MEDIUMAi-inference-server: authentication bypass via unprotected inference endpoint in apiEPSS 0.3%CVE-2024-35585HIGHOxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.EPSS 0.3%CVE-2025-53847MEDIUMA missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7EPSS 0.3%CVE-2026-26027HIGHGLPI has an Unauthenticated Stored XSS via inventoryEPSS 0.3%CVE-2026-46409CRITICALOpenYak local API: unauthenticated CSRF chain leads to Remote Code ExecutionEPSS 0.3%CVE-2024-40408HIGHCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. ThisEPSS 0.3%CVE-2026-60616MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.3%CVE-2025-65828MEDIUMAn unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these deviEPSS 0.3%CVE-2026-5300MEDIUMMissing Authentication for Critical Function in coolercontroldEPSS 0.3%CVE-2025-8450HIGHUnrestricted File Upload in FileCatalystEPSS 0.3%CVE-2026-15063MEDIUMTrustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabledEPSS 0.3%CVE-2024-48952MEDIUMAn issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoinEPSS 0.3%CVE-2024-54176MEDIUMIBM UrbanCode Deploy missing authenticationEPSS 0.3%CVE-2026-100876MEDIUMmathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenticationEPSS 0.3%CVE-2026-83252HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%