Weaknesses of type CWE-306

2,628 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-50025MEDIUMMousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie stateEPSS 0.3%CVE-2024-56469MEDIUMIBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authenticationEPSS 0.3%CVE-2022-45190MEDIUMAn issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing EPSS 0.3%CVE-2024-48442MEDIUMIncorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows aEPSS 0.3%CVE-2026-77339MEDIUMProcess Compose: Browser DNS rebinding lets websites control local process-compose MCP toolsEPSS 0.3%CVE-2025-15509HIGHThe SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.EPSS 0.3%CVE-2026-57128MEDIUMPraisonAI: Unauthenticated Event Injection via SSE `/publish` EndpointEPSS 0.3%CVE-2023-25780MEDIUMStatus Internet Co.,Ltd. PowerBPM - Broken Access ControlEPSS 0.3%CVE-2025-3759HIGHMissing Authentication for Changing Device Configuration in WF2220EPSS 0.2%CVE-2026-32231HIGHZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload dataEPSS 0.2%CVE-2025-1495MEDIUMIBM Business Automation Workflow missing authenticationEPSS 0.2%CVE-2024-3219MEDIUMPure-Python fallback of socket.socketpair() doesn’t authenticate peer connectionEPSS 0.2%CVE-2026-73588HIGHDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnEPSS 0.2%CVE-2021-32453MEDIUMSITEL CAP/PRX information exposureEPSS 0.2%CVE-2026-57910CRITICALWatchGuard Agent improper authentication allows unauthenticated remote code executionEPSS 0.2%CVE-2026-12527MEDIUMA broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmwarEPSS 0.2%CVE-2026-47672MEDIUMepa4all-client: Unauthenticated REST API for Patient Record WritesEPSS 0.2%CVE-2022-48621MEDIUMVulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect EPSS 0.2%CVE-2025-54478HIGHUnauthenticated Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2021-23843HIGHLack of authentication mechanisms on the deviceEPSS 0.2%