Weaknesses of type CWE-306

2,629 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-10906HIGHMagnetism Studios Endurance NSXPC com.MagnetismStudios.endurance.helper loadModuleNamed:WithReply missing authenticationEPSS 0.2%CVE-2025-10672HIGHwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authenticationEPSS 0.2%CVE-2026-88956HIGHBotslab G980H Dashcams Missing Authentication for Critical FunctionEPSS 0.2%CVE-2023-6215HIGHHP Sure Start IFD Protection - BIOS Security UpdateEPSS 0.2%CVE-2025-66445HIGHAuthorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center AnalyzerEPSS 0.2%CVE-2024-47130HIGHMissing Authentication for Critical Function in goTenna ProEPSS 0.2%CVE-2026-12490HIGHBypass of client certificate verification with transfer over TLSEPSS 0.2%CVE-2026-44592CRITICALGradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoningEPSS 0.2%CVE-2025-44039MEDIUMCP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability aEPSS 0.2%CVE-2026-50245HIGHBrickcom Cameras Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-66377HIGHPexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already hEPSS 0.2%CVE-2024-35295MEDIUMA vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between AprEPSS 0.2%CVE-2024-32765MEDIUMQTS, QuTS heroEPSS 0.2%CVE-2024-53701LOWMultiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to bEPSS 0.2%CVE-2022-50979MEDIUMMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via Modbus (RS485)EPSS 0.2%CVE-2026-86502HIGHIn JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote DeEPSS 0.2%CVE-2026-28468HIGHOpenClaw 2026.1.29-beta.1 < 2026.2.14 - Authentication Bypass in Sandbox Browser Bridge ServerEPSS 0.2%CVE-2026-24079HIGHMissing Authentication for Critical Function in Data ModemEPSS 0.2%CVE-2021-26278MEDIUMSensitive information leakage vulnerability in wifi moduleEPSS 0.2%CVE-2026-44211CRITICALCline Kanban Server has a Cross-Origin WebSocket Hijacking VulnerabilityEPSS 0.2%