Weaknesses of type CWE-306

2,593 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2019-13933—A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRPEPSS 1.4%CVE-2020-5373MEDIUMDell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentEPSS 1.4%CVE-2020-5328CRITICALDell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks whEPSS 1.4%CVE-2019-5152HIGHAn exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utiEPSS 1.4%CVE-2020-15127HIGHDenial of service in ContourEPSS 1.4%CVE-2023-27396CRITICALFINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)EPSS 1.4%CVE-2020-6964—In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X EPSS 1.4%CVE-2022-40202CRITICAL The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attEPSS 1.3%CVE-2022-26067MEDIUMAn information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform EPSS 1.3%CVE-2026-45332HIGHAutomad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpointEPSS 1.3%CVE-2025-12548CRITICALGithub.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333EPSS 1.3%CVE-2025-6763CRITICALComet System H3531 Web-based Management setupA.cfg missing authenticationEPSS 1.3%CVE-2022-32157HIGHSplunk Enterprise deployment servers allow unauthenticated forwarder bundle downloadsEPSS 1.3%CVE-2023-35830—STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCEPSS 1.3%CVE-2022-27585CRITICALPassword recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remoteEPSS 1.3%CVE-2022-27586CRITICALPassword recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gaEPSS 1.3%CVE-2022-27582CRITICALPassword recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userleEPSS 1.3%CVE-2022-27584CRITICALPassword recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel EPSS 1.3%CVE-2026-0650CRITICALOpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path NormalizationEPSS 1.3%CVE-2012-10062HIGHXAMPP WebDAV PHP Upload Authentication Bypass RCEEPSS 1.3%