Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2020-14140HIGHWhen Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerabilEPSS 1.0%CVE-2020-10754MEDIUMIt was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when cEPSS 1.0%CVE-2020-23648HIGHAsus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can changeEPSS 1.0%CVE-2016-10364—With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL servEPSS 1.0%CVE-2026-63722HIGHICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpEPSS 1.0%CVE-2023-22441HIGHMissing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alteEPSS 1.0%CVE-2026-25938CRITICALFUXA Unauthenticated Remote Code Execution in Node-RED IntegrationEPSS 1.0%CVE-2023-53964HIGHSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset VulnerabilityEPSS 1.0%CVE-2024-36445CRITICALSwissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.EPSS 1.0%CVE-2023-53771CRITICALMiniDVBLinux 5.4 Unauthenticated Root Password Change via System SetupEPSS 1.0%CVE-2026-0625CRITICALD-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration EndpointEPSS 1.0%CVE-2026-57131CRITICALpraisonai: Jobs API exposes agent-execution endpoints with no authenticationEPSS 1.0%CVE-2025-34224CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Device ModificationEPSS 1.0%CVE-2026-26333CRITICALCalero VeraSMART < 2022 R1 .NET Remoting Arbitrary File Read Leading to ViewState RCEEPSS 1.0%CVE-2025-5095CRITICALBurk Technology ARC Solo Missing Authentication for Critical FunctionEPSS 1.0%CVE-2023-25589CRITICALUnauthenticated Arbitrary User Creation Leads to Complete System CompromiseEPSS 1.0%CVE-2023-1096CRITICALSnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated EPSS 1.0%CVE-2026-57206HIGHSimpleChat plugin validation endpoints missing authentication and authorizationEPSS 1.0%CVE-2025-34414CRITICALEntrust Instant Financial Issuance (IFI) Legacy Remoting Service .NET Remoting RCEEPSS 1.0%CVE-2023-6942HIGHMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 VeEPSS 0.9%