Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-22513MEDIUMdjangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources EPSS 0.8%CVE-2022-27623HIGHMissing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.EPSS 0.8%CVE-2026-84840MEDIUMtsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authenticationEPSS 0.8%CVE-2022-50790MEDIUMSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream DisclosureEPSS 0.8%CVE-2021-27395—A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versioEPSS 0.8%CVE-2023-6595HIGHWhatsUp Gold Unauthenticated Access to an API EndpointEPSS 0.8%CVE-2026-4312CRITICALDrangSoft|GCB/FCB Audit Software - Missing AuthenticationEPSS 0.8%CVE-2023-49617CRITICALMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-63508CRITICALMicrosoft Planetary Computer Pro Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2020-36894CRITICALEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated User Creation VulnerabilityEPSS 0.8%CVE-2026-63455CRITICALAuthentication bypass via spoofed HTTP headers Orchestrator REST APIEPSS 0.8%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.8%CVE-2026-73125CRITICALEbyte NA111-M Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-24124HIGHDragonfly Manager Job API Allows Unauthenticated AccessEPSS 0.8%CVE-2024-2921CRITICALImproper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to tEPSS 0.8%CVE-2025-21524CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported verEPSS 0.8%CVE-2026-82967CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.8%CVE-2026-72593CRITICALdulldusk phpfm - Missing Authentication by Default Allows Full Filesystem AccessEPSS 0.8%CVE-2024-39773MEDIUMAn information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTEPSS 0.8%CVE-2026-7714MEDIUMcrocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authenticationEPSS 0.8%