Weaknesses of type CWE-306

2,627 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-25770HIGHInsufficient authentication in upgrade flowEPSS 0.3%CVE-2025-27256HIGHMissing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to EPSS 0.3%CVE-2026-83252HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.3%CVE-2025-13778HIGHDevice Reboot ControlEPSS 0.3%CVE-2025-36756MEDIUMDevice Takeover vulnerability in SolaX CloudEPSS 0.3%CVE-2026-81238HIGHDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unautheEPSS 0.3%CVE-2025-10746MEDIUMIntegrate Dynamics 365 CRM <= 1.0.9 - Missing AuthorizationEPSS 0.3%CVE-2026-55837MEDIUMdbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensEPSS 0.3%CVE-2026-60322MEDIUMVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported vEPSS 0.3%CVE-2026-42341CRITICALFOSSBilling has an unauthenticated payment bypass via IPN callback forgeryEPSS 0.3%CVE-2026-60682MEDIUMVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that isEPSS 0.3%CVE-2025-0256MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosureEPSS 0.3%CVE-2019-25678HIGHC4G BLIS 3.4 SQL Injection via users_select.phpEPSS 0.3%CVE-2026-76902MEDIUMCordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`EPSS 0.3%CVE-2026-61247MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.3%CVE-2025-11198HIGHSecurity Director Policy Enforcer: An unrestricted API allows a network-based unauthenticated attacker to deploy malicious vSRX images to VMWare NSX ServerEPSS 0.3%CVE-2026-22192HIGHVoltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorageEPSS 0.3%CVE-2026-49174MEDIUMDNS Client Tampering VulnerabilityEPSS 0.3%CVE-2026-73842CRITICALOpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutationEPSS 0.3%