Weaknesses of type CWE-306

2,628 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-9815HIGHalaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authenticationEPSS 0.3%CVE-2024-57055MEDIUMServer-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain servEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.3%CVE-2026-13306MEDIUMAutel MaxiCharger AC Elite Home USB Authentication Bypass VulnerabilityEPSS 0.3%CVE-2026-77974HIGHSoftish C6 Ear Camera and EarVision Android Application Missing authentication for critical functionEPSS 0.3%CVE-2025-1754MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.3%CVE-2025-0275MEDIUMHCL BigFix Mobile 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2026-86486LOWIn JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blankEPSS 0.3%CVE-2026-18185HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2025-0274MEDIUMHCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2026-94455HIGHUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API keyEPSS 0.3%CVE-2026-60574MEDIUMVulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affecEPSS 0.3%CVE-2024-6347MEDIUMUnauthorized access to ECU functionalityEPSS 0.3%CVE-2026-62474MEDIUMVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versionEPSS 0.3%CVE-2026-81455HIGHDell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An uEPSS 0.3%CVE-2026-59148HIGHMockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftEPSS 0.3%CVE-2026-1919MEDIUMBooktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpointsEPSS 0.3%CVE-2025-48572HIGHIn multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to locaEPSS 0.3%KEVCVE-2025-7706MEDIUMImproper Access Control in TUBITAK BILGEM's LiderahenkEPSS 0.3%CVE-2026-50025MEDIUMMousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie stateEPSS 0.3%