Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2020-3333MEDIUMCisco Application Services Engine Software Unauthenticated Event Policies Update VulnerabilityEPSS 1.0%CVE-2025-36535CRITICALAutomationDirect MB-Gateway Missing Authentication for Critical FunctionEPSS 1.0%CVE-2022-41272CRITICALAn unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NeEPSS 1.0%CVE-2024-9164CRITICALMissing Authentication for Critical Function in GitLabEPSS 1.0%CVE-2026-12046CRITICALpgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code executionEPSS 1.0%CVE-2019-13549—Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected syEPSS 1.0%CVE-2014-125113CRITICALDell/Quest KACE K1000 Unauthenticated File Upload RCEEPSS 1.0%CVE-2022-44784HIGHAn issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the AxEPSS 1.0%CVE-2017-6873—A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulatEPSS 1.0%CVE-2024-28179CRITICALJupyter Server Proxy's Websocket Proxying does not require authenticationEPSS 1.0%CVE-2019-16004MEDIUMCisco Vision Dynamic Signage Director Authentication Bypass VulnerabilityEPSS 1.0%CVE-2025-27647CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users WitEPSS 1.0%CVE-2023-41187HIGHD-Link DAP-1325 HNAP Missing Authentication Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-43999CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executeEPSS 1.0%CVE-2022-44000CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbEPSS 1.0%CVE-2023-39466MEDIUMTriangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure VulnerabilityEPSS 1.0%CVE-2021-26928MEDIUMBIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which mEPSS 1.0%CVE-2026-21992CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services ManagEPSS 1.0%CVE-2026-64921HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2025-34218CRITICALVasion Print (formerly PrinterLogic) Exposed Internal Docker InstanceEPSS 1.0%