Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-65010HIGHMissing authorizations for admin panel password change in WODESYS WD-R608U routerEPSS 0.2%CVE-2025-55073MEDIUMMS Teams plugin OAuth allows editing arbitrary postsEPSS 0.2%CVE-2023-4516HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker tEPSS 0.2%CVE-2025-30040CRITICALMissing authentication in API returning request logs containing session IDsEPSS 0.2%CVE-2026-60600HIGHVulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version tEPSS 0.2%CVE-2023-25493MEDIUMA potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products EPSS 0.2%CVE-2026-75060HIGHIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP toolsEPSS 0.2%CVE-2026-6348CRITICALSimopro Technology|WinMatrix - Missing AuthenticationEPSS 0.2%CVE-2026-60765HIGHVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are EPSS 0.2%CVE-2025-55581HIGHD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. EPSS 0.2%CVE-2025-0129CRITICALPrisma Access Browser: Inappropriate control behavior in Prisma Access BrowserEPSS 0.2%CVE-2026-24259MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A succeEPSS 0.2%CVE-2025-54158HIGHMissing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local userEPSS 0.2%CVE-2026-1264HIGHIBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access ControlsEPSS 0.2%CVE-2026-4522MEDIUMMissing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affeEPSS 0.2%CVE-2024-55538MEDIUMSensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before buildEPSS 0.2%CVE-2025-64770HIGHMissing Authentication for ONVIF in iCam CamerasEPSS 0.2%CVE-2025-30041CRITICALMissing authentication in APIs returning statistical data along with session IDsEPSS 0.2%CVE-2023-52949MEDIUMMissing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent befoEPSS 0.2%CVE-2025-30039CRITICALMissing authentication in API returning a list of all active sessionsEPSS 0.2%