Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-35865HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication EPSS 1.9%CVE-2026-26235HIGHJUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing AuthenticationEPSS 1.9%CVE-2026-58126CRITICALPACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP ServiceEPSS 1.8%CVE-2021-20198—A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift ConEPSS 1.8%CVE-2026-4810CRITICALRemote Code Execution in Google Agent Development Kit (ADK)EPSS 1.8%CVE-2024-8321MEDIUMMissing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attaEPSS 1.8%CVE-2025-34120HIGHLimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup PayloadEPSS 1.8%CVE-2021-32800HIGHBypass of Two Factor Authentication in Nextcloud serverEPSS 1.8%CVE-2023-46819MEDIUMApache OFBiz: Execution of Solr plugin queries without authenticationEPSS 1.8%CVE-2022-39425HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 1.8%CVE-2018-4840—A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 EEPSS 1.8%CVE-2019-1876MEDIUMCisco Wide Area Application Services Software HTTPS Proxy Authentication Bypass VulnerabilityEPSS 1.8%CVE-2022-34321HIGHApache Pulsar: Improper Authentication for Pulsar Proxy Statistics EndpointEPSS 1.8%CVE-2020-10282CRITICALRVD#3316: No authentication in MAVLink protocolEPSS 1.8%CVE-2022-34858CRITICALWordPress OAuth 2.0 client for SSO plugin <= 1.11.3 - Authentication Bypass vulnerabilityEPSS 1.8%CVE-2021-34538—Apache Hive Security vulnerability in Hive with UDFsEPSS 1.8%CVE-2014-125126CRITICALSimple E-Document Arbitrary File Upload RCEEPSS 1.7%CVE-2026-75791HIGHAuthentication bypass vulnerabilityEPSS 1.7%CVE-2022-27169HIGHAn information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16EPSS 1.7%CVE-2022-45481CRITICALThe default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with noEPSS 1.7%