Weaknesses of type CWE-306

2,628 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-6895MEDIUMInsecure Account Profile ManagementEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%CVE-2026-3194LOWChia Blockchain RPC Server Master Passphrase get_private_key missing authenticationEPSS 0.2%CVE-2022-3312MEDIUMInsufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass manEPSS 0.2%CVE-2025-68716HIGHKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configuEPSS 0.2%CVE-2023-48426CRITICALChromecast Bootloader & Kernel-level code-execution including compromise of user-dataEPSS 0.2%CVE-2025-53034MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.2%CVE-2024-2104HIGHJBL: Improper BLE security configurations and lack of authentication on the device's GATT serverEPSS 0.2%CVE-2023-6949MEDIUMA Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 EPSS 0.2%CVE-2026-6017HIGHMissing Authentication for Critical Function in KAON PG5298EPSS 0.2%CVE-2025-9312CRITICALImproper Certificate-Based Authentication Enforcement in Multiple WSO2 ProductsEPSS 0.2%CVE-2026-24177HIGHNVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of thEPSS 0.2%CVE-2025-1272HIGHKernel: secure boot does not automatically enable kernel lockdownEPSS 0.2%CVE-2025-5719MEDIUMThe wallet has an authentication bypass vulnerability that allows access to specific pages.EPSS 0.2%CVE-2026-8706MEDIUMSensitive user data could be leaked to other applications through Reader modeEPSS 0.2%CVE-2026-71568MEDIUMBMCtest exposes Ironic without authentication and TLS during the testEPSS 0.2%CVE-2025-14038HIGHEDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an atEPSS 0.2%CVE-2025-64307HIGHBrightpick Mission Control / Internal Logic Control Missing Authentication for Critical FunctionEPSS 0.2%CVE-2024-45483HIGHMissing GRUB password in B&R APROLEPSS 0.2%CVE-2026-1920MEDIUMBooktics <= 1.0.16 - Missing Authorization to Addon Plugin InstallationEPSS 0.2%