Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-12444MEDIUMIncorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in sEPSS 0.2%CVE-2025-30039CRITICALMissing authentication in API returning a list of all active sessionsEPSS 0.2%CVE-2026-55529MEDIUMPraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP serverEPSS 0.2%CVE-2025-15515MEDIUMThe authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a loEPSS 0.2%CVE-2025-10991HIGHRoot Access via UARTEPSS 0.2%CVE-2026-96455HIGHReachy Mini daemon allows unauthenticated remote code execution through the app installation endpointEPSS 0.2%CVE-2025-62674HIGHMissing Authentication for RTSP in iCam CamerasEPSS 0.2%CVE-2020-9062—Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2026-81441MEDIUMDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An EPSS 0.2%CVE-2024-22449MEDIUM Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileEPSS 0.2%CVE-2026-60884MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.2%CVE-2026-11238MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicEPSS 0.2%CVE-2026-6369MEDIUMExposed Session Token in canonical-livepatch client snapEPSS 0.2%CVE-2024-39707MEDIUMInsyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could leEPSS 0.2%CVE-2026-16646MEDIUMPanKM - Critical - Unsupported - SA-CONTRIB-2026-083EPSS 0.2%CVE-2026-42095MEDIUMbookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.EPSS 0.2%CVE-2026-59913HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulneraEPSS 0.2%CVE-2020-12492LOWWifi information acquisition vulnerability in Framework ServicesEPSS 0.2%CVE-2025-67780MEDIUMSpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gREPSS 0.2%CVE-2026-32041HIGHOpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth BootstrapEPSS 0.2%