Weaknesses of type CWE-306

2,595 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2016-6541—TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributesEPSS 1.1%CVE-2025-11942MEDIUM70mai X200 Pairing missing authenticationEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2024-39273CRITICALA firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP requeEPSS 1.1%CVE-2026-54130CRITICALM365 Copilot Information Disclosure VulnerabilityEPSS 1.1%CVE-2022-30230CRITICALA vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticEPSS 1.1%CVE-2020-15799—A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT sEPSS 1.1%CVE-2016-6549—Zizai Tech Nut allows for unauthenticated Bluetooth pairingEPSS 1.1%CVE-2022-29881MEDIUMA vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employEPSS 1.1%CVE-2025-7862MEDIUMTOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authenticationEPSS 1.1%CVE-2026-75854CRITICALArcadeDB Redis Wire-Protocol Plugin Missing AuthenticationEPSS 1.1%CVE-2022-45140CRITICALWAGO: Missing Authentication for Critical Function EPSS 1.1%CVE-2022-42785CRITICALWiesemann & Theis: Authentication bypass in Com-Server familyEPSS 1.1%CVE-2025-4268MEDIUMTOTOLINK A720R cstecgi.cgi missing authenticationEPSS 1.1%CVE-2025-41703HIGHPhoenix Contact: UPS Shutdown via Unauthenticated Modbus CommandEPSS 1.1%CVE-2020-36892CRITICALEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated Privilege EscalationEPSS 1.1%CVE-2021-3589—An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can acEPSS 1.0%CVE-2025-48814HIGHRemote Desktop Licensing Service Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2023-33553CRITICALAn issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulEPSS 1.0%CVE-2021-1396CRITICALCisco Application Services Engine Unauthorized Access VulnerabilitiesEPSS 1.0%