Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-40620CRITICALSenseLive X3050 Missing authentication for critical functionEPSS 0.8%CVE-2026-50516CRITICALMicrosoft Azure Kubernetes Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2019-10941—A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires adminiEPSS 0.8%CVE-2025-9971CRITICALPlanet Technology|Industrial Cellular Gateway - Missing AuthenticationEPSS 0.8%CVE-2025-4015MEDIUM20120630 Novel-Plus SessionController.java list missing authenticationEPSS 0.8%CVE-2022-47703HIGHTIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, anEPSS 0.8%CVE-2026-89261MEDIUMMoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management EndpointsEPSS 0.8%CVE-2024-8196CRITICALMissing Authentication for Critical Function in mintplex-labs/anything-llmEPSS 0.8%CVE-2026-18941HIGHFeast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authenticationEPSS 0.8%CVE-2020-10044—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attackEPSS 0.8%CVE-2026-61514CRITICALPuwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456EPSS 0.8%CVE-2026-82452CRITICALrust-iot-platform Authentication Bypass via Missing Request GuardsEPSS 0.8%CVE-2026-69703CRITICALAtlas-Livre Unauthenticated Access via Admin Controllers Missing ExitEPSS 0.8%CVE-2026-70552CRITICALMaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.phpEPSS 0.8%CVE-2023-4815HIGHMissing Authentication for Critical Function in answerdev/answerEPSS 0.8%CVE-2026-35053CRITICALOneUptime: Unauthenticated Workflow Execution via ManualAPIEPSS 0.8%CVE-2025-21535CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%CVE-2026-44338HIGHPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow executionEPSS 0.8%CVE-2023-25570HIGHApollo has potential access control security issue in eurekaEPSS 0.8%CVE-2022-46732CRITICALCVE-2022-46732EPSS 0.8%