Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-60975HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affeEPSS 0.1%CVE-2026-22174MEDIUMOpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP ProbeEPSS 0.1%CVE-2026-19267MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2026-84403MEDIUMBotslab G980H Dashcams Missing Authentication for Critical FunctionEPSS 0.1%CVE-2026-24062HIGHInsufficient XPC Client validation leading to local privilege escalation in Arturia Software CenterEPSS 0.1%CVE-2026-12663HIGHControlFLASH ® – Improper Access ControlEPSS 0.1%CVE-2026-21767MEDIUMHCL BigFix Platform is affected by insufficient authenticationEPSS 0.1%CVE-2026-47122MEDIUMSparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injectionEPSS 0.1%CVE-2025-31963LOWHCL BigFix IVR is impacted by improper authentication and missing CSRF protectionEPSS 0.1%CVE-2025-47357HIGHMissing Authentication for Critical Function in SMSSEPSS 0.1%CVE-2026-24088HIGHMissing Authentication for Critical Function in BootEPSS 0.1%CVE-2025-48608MEDIUMIn isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead toEPSS 0.1%CVE-2026-24090HIGHMissing Authentication for Critical Function in HLOSEPSS 0.1%CVE-2026-7395HIGHAsset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to EPSS —CVE-2026-102362MEDIUMmall4j through 4.0 Missing Authentication in Product Review DeletionEPSS —CVE-2026-49994CRITICALBluehood: Missing authentication on Bluehood API routes when web auth is enabledEPSS —CVE-2026-102245MEDIUMMODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authenticationEPSS —CVE-2026-101077CRITICALNetcore NR289-GE boa_temp process_request missing authenticationEPSS —CVE-2026-102363MEDIUMmall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order NumberEPSS —CVE-2026-53988CRITICALDockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook EndpointsEPSS —