Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-22526CRITICALMissing authentication for API in Carlo Gavazzi UWP 3.0 Car Park ServerEPSS 0.8%CVE-2017-6872—A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 2EPSS 0.8%CVE-2024-40717HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updaEPSS 0.8%CVE-2026-90513MEDIUMsimalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authenticationEPSS 0.8%CVE-2026-47281CRITICALVisual Studio Code Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-1775HIGHMissing Authentication for Critical Function in Labkotec LID-3300IPEPSS 0.8%CVE-2026-87924MEDIUMRizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authenticationEPSS 0.8%CVE-2026-86293MEDIUMSourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authenticationEPSS 0.8%CVE-2025-34071CRITICALGFI Kerio Control Unsigned System Image Upload Root Code ExecutionEPSS 0.8%CVE-2026-56262MEDIUMCrawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API ServerEPSS 0.8%CVE-2026-82472HIGHDocumenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdfEPSS 0.8%CVE-2024-22212CRITICALNextcloud global site selector authentication bypassEPSS 0.8%CVE-2026-25775CRITICALSenseLive X3050 Missing authentication for critical functionEPSS 0.8%CVE-2026-88018CRITICALrclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassEPSS 0.8%CVE-2026-57139CRITICALPraisonAI MCPServer exposes unauthenticated HTTP tools/callEPSS 0.8%CVE-2023-51947CRITICALImproper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types EPSS 0.8%CVE-2023-27497CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)EPSS 0.8%CVE-2023-22069CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%CVE-2026-85636MEDIUMjofpin trape Login Endpoint stats.py missing authenticationEPSS 0.8%CVE-2022-30229HIGHA vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticEPSS 0.7%