Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-51987CRITICALD-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with emptyEPSS 0.9%CVE-2026-5944MEDIUMCisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API AccessEPSS 0.9%CVE-2016-6540—TrackR Bravo is missing authentication for the cloud service and allows querying or sending of GPS data from unauthenticated usersEPSS 0.9%CVE-2026-34072HIGHcronmaster: Middleware authentication bypass enabling unauthorized page access and server-action executionEPSS 0.9%CVE-2023-7329HIGHTinycontrol LAN Controller v3 (LK3) Remote DoSEPSS 0.9%CVE-2026-57123CRITICALPraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired inEPSS 0.9%CVE-2026-56163CRITICALMicrosoft Azure Kubernetes Service Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-43920MEDIUMFOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance executionEPSS 0.9%CVE-2016-9496—Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication to access certain pagesEPSS 0.9%CVE-2025-34068CRITICALSamsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 ParametersEPSS 0.9%CVE-2023-27571MEDIUMAn issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download fuEPSS 0.9%CVE-2026-57127CRITICALpraisonai: recipe serve auth middleware silently disables itself when no secret is setEPSS 0.9%CVE-2019-10915—A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA AEPSS 0.9%CVE-2021-34870MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_EPSS 0.9%CVE-2025-32978HIGHQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 0.9%CVE-2026-48252HIGHAdobe Experience Manager | Missing Authentication for Critical Function (CWE-306)EPSS 0.9%CVE-2024-33616MEDIUMAdmin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. SharpEPSS 0.9%CVE-2020-27285MEDIUMThe default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database withoutEPSS 0.9%CVE-2026-22552CRITICALePower epower.ie Missing Authentication for Critical FunctionEPSS 0.9%CVE-2026-75854CRITICALArcadeDB Redis Wire-Protocol Plugin Missing AuthenticationEPSS 0.9%