Weaknesses of type CWE-306

2,593 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2012-10062HIGHXAMPP WebDAV PHP Upload Authentication Bypass RCEEPSS 1.3%CVE-2022-46414CRITICALAn issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command exeEPSS 1.3%CVE-2022-33138—A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All veEPSS 1.3%CVE-2023-38186HIGHWindows Mobile Device Management Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2023-27060CRITICALLightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.EPSS 1.3%CVE-2022-29226CRITICALTrivial authentication bypass in EnvoyEPSS 1.3%CVE-2023-23906HIGHMissing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unautEPSS 1.3%CVE-2021-44222—A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems dEPSS 1.3%CVE-2022-27645HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. AuthentiEPSS 1.3%CVE-2022-29951CRITICALJTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on eEPSS 1.3%CVE-2022-41331CRITICALA missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a EPSS 1.3%CVE-2026-20803HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2025-8286CRITICALGüralp Systems FMUS Series and MIN Series DevicesEPSS 1.3%CVE-2023-47674CRITICALMissing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite oEPSS 1.3%CVE-2023-28326CRITICALApache OpenMeetings: allows user impersonationEPSS 1.3%CVE-2021-27255MEDIUMThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. AEPSS 1.3%CVE-2022-26303HIGHAn external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.0EPSS 1.3%CVE-2022-26043HIGHAn external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform VEPSS 1.3%CVE-2021-43447HIGHONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attEPSS 1.3%CVE-2022-20858CRITICALCisco Nexus Dashboard Unauthorized Access VulnerabilitiesEPSS 1.3%