Weaknesses of type CWE-306

2,594 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-28771—Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send maliciouEPSS 1.1%CVE-2025-21623HIGHClipBucket V5 Unauthenticated Template Directory Update to Denial-of-ServiceEPSS 1.1%CVE-2018-14796—Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be usedEPSS 1.1%CVE-2019-18230—Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticatEPSS 1.1%CVE-2020-10605—Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.EPSS 1.1%CVE-2023-27747HIGHBlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access seEPSS 1.1%CVE-2023-21743MEDIUMMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2023-36851MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary filesEPSS 1.1%KEVCVE-2022-38168CRITICALBroken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackEPSS 1.1%CVE-2025-3699CRITICALMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A EPSS 1.1%CVE-2025-26339CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 aEPSS 1.1%CVE-2025-26344CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to versionEPSS 1.1%CVE-2025-26347CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.EPSS 1.1%CVE-2025-26341CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2EPSS 1.1%CVE-2025-26345CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.EPSS 1.1%CVE-2025-26342CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2EPSS 1.1%CVE-2021-20998CRITICALWAGO: Managed Switches: Unauthorized creation of user accountsEPSS 1.1%CVE-2022-2242CRITICALKUKA V/KSS WoV SH access control vulnerabilityEPSS 1.1%CVE-2023-23453CRITICALMissing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to EPSS 1.1%CVE-2023-23452CRITICALMissing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to EPSS 1.1%