Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-5951HIGHDeep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service VulnerabilityEPSS 0.8%CVE-2023-38379—The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin passworEPSS 0.8%CVE-2022-22809—A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in aEPSS 0.8%CVE-2025-59358HIGHDenial of Service via Unauthorized Access to Chaos Mesh debugging serverEPSS 0.8%CVE-2025-55108CRITICALBMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code executionEPSS 0.8%CVE-2024-47138CRITICALmySCADA myPRO Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-77915CRITICALrConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.phpEPSS 0.8%CVE-2025-9574CRITICALMissing Authentication VulnerabilityEPSS 0.8%CVE-2026-84839MEDIUMtsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authenticationEPSS 0.8%CVE-2026-54103CRITICALU.S. GAO EPDS and CBCA EDS unauthenticated password changeEPSS 0.8%CVE-2026-9336MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.8%CVE-2018-25412CRITICALDelta Sql 1.8.2 Arbitrary File Upload via docs_upload.phpEPSS 0.8%CVE-2025-14567MEDIUMhaxxorsid Stock-Management-System employees missing authenticationEPSS 0.8%CVE-2026-91002MEDIUMstamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authenticationEPSS 0.8%CVE-2026-26944HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 0.8%CVE-2026-78239CRITICALXiiaozet LK100W Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2026-15192MEDIUMmettle sendportal APIv1 Webhooks mailjet missing authenticationEPSS 0.8%CVE-2026-4959MEDIUMOpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authenticationEPSS 0.8%CVE-2022-22526CRITICALMissing authentication for API in Carlo Gavazzi UWP 3.0 Car Park ServerEPSS 0.8%