Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-22047HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affectEPSS 77.0%CVE-2019-5620—ABB MicroSCADA Pro SYS600 Missing Authentication for Critical FunctionEPSS 70.1%CVE-2023-28461CRITICALArray Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSEPSS 68.1%KEVCVE-2021-29442HIGHAuthentication bypassEPSS 66.6%CVE-2022-3229CRITICALBecause the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenEPSS 66.4%CVE-2025-8943CRITICALUnsupervised OS command execution leads to remote code execution by unauthenticated network attackersEPSS 65.8%CVE-2026-23744CRITICALREC in MCPJam inspector due to HTTP Endpoint exposesEPSS 64.8%CVE-2024-46506CRITICALNetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lEPSS 62.0%CVE-2024-8956CRITICALPTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient AuthenticationEPSS 61.3%KEVCVE-2022-45933CRITICALKubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authenticEPSS 51.7%CVE-2025-58434CRITICALFlowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account TakeoverEPSS 49.9%CVE-2022-23227CRITICALNUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary usersEPSS 48.5%KEVCVE-2021-41266HIGHAuthentication bypass issue in the Operator ConsoleEPSS 48.4%CVE-2025-71257MEDIUMBMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication BypassEPSS 44.6%CVE-2025-49596CRITICALMCP Inspector proxy server lacks authentication between the Inspector client and proxyEPSS 44.5%CVE-2025-52665CRITICALA malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, tEPSS 41.0%CVE-2022-35871HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202EPSS 39.2%CVE-2022-26833CRITICALAn improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A speciaEPSS 37.6%CVE-2026-26190CRITICALMilvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System CompromiseEPSS 36.9%CVE-2021-22652—Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacEPSS 36.8%