Weaknesses of type CWE-306

2,593 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2019-6820HIGHA CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IPEPSS 1.3%CVE-2019-13525—In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to EPSS 1.3%CVE-2020-12505HIGHWAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07EPSS 1.2%CVE-2020-10038—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attackEPSS 1.2%CVE-2022-39426HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 1.2%CVE-2026-27182HIGHSaturn Remote Mouse Server UDP Command Injection RCEEPSS 1.2%CVE-2024-43488HIGHVisual Studio Code extension for Arduino Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-8320MEDIUMMissing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attaEPSS 1.2%CVE-2019-6533—Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway vEPSS 1.2%CVE-2025-34223CRITICALVasion Print (formerly PrinterLogic) Insecure Installation CredentialsEPSS 1.2%CVE-2019-16003MEDIUMCisco UCS Director Information Disclosure VulnerabilityEPSS 1.2%CVE-2019-15282MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 1.2%CVE-2024-5749HIGHCertain HP DesignJet products – Credential reflectionEPSS 1.2%CVE-2020-3461MEDIUMCisco Data Center Network Manager Information Disclosure VulnerabilityEPSS 1.2%CVE-2026-33231HIGHNLTK has unauthenticated remote shutdown in nltk.app.wordnet_appEPSS 1.2%CVE-2022-32251HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification foEPSS 1.2%CVE-2021-41104HIGHweb_server allows OTA update without checking user defined basic auth username & passwordEPSS 1.2%CVE-2024-23618CRITICALArris SURFboard SBG6950AC2 Arbitrary Code Execution VulnerabilityEPSS 1.2%CVE-2025-59090CRITICALUnauthenticated SOAP API in dormakaba Kaba exos 9300EPSS 1.2%CVE-2022-26026HIGHA denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.EPSS 1.2%