Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-34111CRITICALTiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCEEPSS 2.2%CVE-2026-2624CRITICALAuthentication Bypass in ePati's Antikor NGFWEPSS 2.2%CVE-2025-34119HIGHEasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43EPSS 2.2%CVE-2018-0181HIGHCisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent Software Redis Server Unauthenticated Access VulnerabilityEPSS 2.2%CVE-2014-125124CRITICALPandora FMS <= 5.0RC1 Anyterm Unauthenticated Command InjectionEPSS 2.1%CVE-2020-7389MEDIUMSage X3 Syracuse Missing Authentication for Critical Function in Developer EnvironmentEPSS 2.1%CVE-2026-56270HIGHFlowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod EndpointEPSS 2.0%CVE-2017-3217—CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / resellerEPSS 2.0%CVE-2024-21855CRITICALA lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arEPSS 2.0%CVE-2023-39457CRITICALTriangle MicroWorks SCADA Data Gateway Missing Authentication VulnerabilityEPSS 2.0%CVE-2023-2231CRITICALMAXTECH MAX-G866ac Remote Management missing authenticationEPSS 2.0%CVE-2019-18572HIGHThe RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper AuthenticatioEPSS 2.0%CVE-2020-7589—A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker readinEPSS 2.0%CVE-2026-61808CRITICALLightRAG: Missing Authentication for Critical API Functions in Default ConfigurationEPSS 2.0%CVE-2015-7559LOWIt was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker loEPSS 2.0%CVE-2014-9197—Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical FunctionEPSS 2.0%CVE-2025-34110CRITICALColoradoFTP Server <= 1.3 Build 8 Path Traversal Information DisclosureEPSS 1.9%CVE-2022-39412HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affEPSS 1.9%CVE-2026-58127CRITICALPACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP ServiceEPSS 1.9%CVE-2022-25251CRITICALPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 1.9%