Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-50608LOWAuthentication Vulnerability in NitroSense and PredatorSense SoftwareEPSS 0.2%CVE-2026-46555HIGHWhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationEPSS 0.2%CVE-2026-84400LOWCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2021-26278MEDIUMSensitive information leakage vulnerability in wifi moduleEPSS 0.2%CVE-2026-44211CRITICALCline Kanban Server has a Cross-Origin WebSocket Hijacking VulnerabilityEPSS 0.2%CVE-2022-50980MEDIUMMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via CANEPSS 0.2%CVE-2026-50604MEDIUMUnauthenticated Access Vulnerability in NitroSense and PredatorSense SoftwareEPSS 0.2%CVE-2025-30048MEDIUMUnauthenticated access to module configuration endpointEPSS 0.2%CVE-2025-30037HIGHMissing authentication in APIs allowing data retrieval and modificationEPSS 0.2%CVE-2025-44004HIGHUnauthenticated Channel Subscription Creation in Mattermost Confluence PluginEPSS 0.2%CVE-2021-21535HIGHDell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local unauthenticated attEPSS 0.2%CVE-2026-41477HIGHDeskflow: Local privilege escalation via unauthenticated IPCEPSS 0.2%CVE-2026-27846MEDIUMMissing authentication in Linksys MR9600, Linksys MX4200EPSS 0.2%CVE-2025-40816HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.2%CVE-2025-9214MEDIUMA missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or moEPSS 0.2%CVE-2025-32063MEDIUMEnabling SSH server on Infotainment ECUEPSS 0.2%CVE-2026-19397HIGHMissing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the hosEPSS 0.2%CVE-2026-61742CRITICALDBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL executionEPSS 0.2%CVE-2026-41047MEDIUMInformation leak via “diff” methods in qSnapperEPSS 0.2%CVE-2026-22727HIGHCloud Foundry unprotected internal endpointsEPSS 0.2%