Weaknesses of type CWE-306

2,593 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2020-3392HIGHCisco IoT Field Network Director Missing API Authentication VulnerabilityEPSS 1.5%CVE-2021-22772—A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), EaseEPSS 1.5%CVE-2024-45274CRITICALMB connect line/Helmholz: Remote code execution via confnet serviceEPSS 1.5%CVE-2022-1300CRITICALMissing authentication in TRUMPF products may result in corruption of dataEPSS 1.5%CVE-2019-6542—ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated usEPSS 1.5%CVE-2019-1629MEDIUMCisco Integrated Management Controller Arbitrary File Write VulnerabilityEPSS 1.5%CVE-2026-47212MEDIUMSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionEPSS 1.5%CVE-2023-44413MEDIUMD-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service VulnerabilityEPSS 1.5%CVE-2024-5718HIGHLogsign Unified SecOps Platform Missing Authentication Remote Code Execution VulnerabilityEPSS 1.5%CVE-2026-32985CRITICALXerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code ExecutionEPSS 1.5%CVE-2023-42121CRITICALControl Web Panel Missing Authentication Remote Code Execution VulnerabilityEPSS 1.5%CVE-2026-85688CRITICALTEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN DesignerEPSS 1.5%CVE-2020-10265CRITICALRVD#1443: UR dashboard server enables unauthenticated remote control of core robot functionsEPSS 1.5%CVE-2020-12506CRITICALWAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03EPSS 1.5%CVE-2025-34221CRITICALVasion Print (formerly PrinterLogic)EPSS 1.5%CVE-2021-22279CRITICALOmniCore RobotWare Missing Authentication VulnerabilityEPSS 1.4%CVE-2017-15123MEDIUMA flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated EPSS 1.4%CVE-2021-1246MEDIUMCisco Finesse OpenSocial Gadget Editor Unauthenticated Access VulnerabilityEPSS 1.4%CVE-2024-39608CRITICALA firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP requestEPSS 1.4%CVE-2023-5376HIGHTFTP Without AuthenticationEPSS 1.4%