Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-0247MEDIUMPrisma Access Agent Endpoint DLP: Authorization Bypass VulnerabilitiesEPSS 0.2%CVE-2021-26280HIGHPermission bypass vulnerability in permission manager moduleEPSS 0.2%CVE-2026-11535CRITICALAn unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to thEPSS 0.2%CVE-2026-9045HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise foEPSS 0.1%CVE-2026-42283HIGHDevSpace UI Server WebSocket CheckOrigin does not validate sourceEPSS 0.1%CVE-2026-12763MEDIUMLangflow is vulnerable to authentication bypass and insufficient session expirationEPSS 0.1%CVE-2026-46685MEDIUMRustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on consoleEPSS 0.1%CVE-2026-60569MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0EPSS 0.1%CVE-2024-45355MEDIUMXiaomi phone framework has unauthorized access vulnerabilityEPSS 0.1%CVE-2024-9062HIGHmacOS Archify: Local Privilege EscalationEPSS 0.1%CVE-2026-70806HIGHVulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.1%CVE-2026-92254MEDIUMWatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTLEPSS 0.1%CVE-2026-70693MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.1%CVE-2025-15567MEDIUMInsufficient protection mechanisms in the Health Module may lead to partial information disclosure.EPSS 0.1%CVE-2025-30650HIGHJunos OS: Privileged local user can gain access to a Linux-based FPC as rootEPSS 0.1%CVE-2026-6511MEDIUMDuring an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for WindowsEPSS 0.1%CVE-2025-41686HIGHImproper File Permissions Allow Local Privilege EscalationEPSS 0.1%CVE-2026-60902HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affectEPSS 0.1%CVE-2026-70711LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.1%CVE-2019-25483HIGHComtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell EscapeEPSS 0.1%