Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-33788HIGHJunos OS Evolved: Local, authenticated attacker can gain privileged access to FPCsEPSS 0.2%CVE-2025-12436MEDIUMPolicy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extensioEPSS 0.2%CVE-2023-52947MEDIUMMissing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3EPSS 0.2%CVE-2026-45610MEDIUMWWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FAEPSS 0.2%CVE-2026-24229HIGHNVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or EPSS 0.2%CVE-2025-58318MEDIUMDIAView - Authentication Bypass VulnerabilityEPSS 0.2%CVE-2024-2860HIGHThe PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker EPSS 0.2%CVE-2025-23356HIGHNVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code executEPSS 0.2%CVE-2026-60596LOWVulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version EPSS 0.2%CVE-2024-12957HIGHA file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 SEPSS 0.2%CVE-2025-14058LOWA potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical accEPSS 0.2%CVE-2023-5935HIGHMissing authentication for local web interface in Arc before v1.6.0EPSS 0.2%CVE-2025-47272MEDIUMPhoenixCart Vulnerable to Account Deletion Without Password ConfirmationEPSS 0.2%CVE-2026-94540HIGHDesktopSMS 1.11.0 Unauthorized Access via Local ServiceEPSS 0.2%CVE-2026-76137MEDIUMMissing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a rEPSS 0.2%CVE-2026-39848MEDIUMDockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database ManipulationEPSS 0.2%CVE-2024-45356HIGHXiaomi phone framework has unauthorized access vulnerabilityEPSS 0.2%CVE-2026-60595MEDIUMVulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The suppoEPSS 0.2%CVE-2026-60712MEDIUMVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.2%CVE-2026-54776MEDIUMCoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgradeEPSS 0.2%