Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-68715CRITICALAn issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/seEPSS 0.7%CVE-2026-85695CRITICALFastChat Unauthenticated Worker Registration SSRF and Model SpoofingEPSS 0.7%CVE-2022-2474CRITICALAuthentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allowEPSS 0.7%CVE-2023-49255CRITICALRouter console accessible without authenticationEPSS 0.7%CVE-2024-31218CRITICALMissing Authentication for Critical Function in Webhood backendEPSS 0.7%CVE-2026-40344HIGHMinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer UploadsEPSS 0.7%CVE-2023-4506LOWActive Directory Integration / LDAP Integration <= 4.1.10 - LDAP PassbackEPSS 0.7%CVE-2023-4505LOWStaff / Employee Business Directory for Active Directory <= 1.2.3 - Authenticated (Admin+) LDAP PassbackEPSS 0.7%CVE-2026-7415CRITICALOpen MQTT orchestration without read/write ACLs in Yarbo robot firmwareEPSS 0.7%CVE-2026-7723MEDIUMPrefectHQ prefect WebSocket Endpoint in missing authenticationEPSS 0.7%CVE-2026-90896HIGHMissing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PIIEPSS 0.7%CVE-2026-63087CRITICALGrafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install EndpointEPSS 0.7%CVE-2025-9152CRITICALImproper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR EndpointEPSS 0.7%CVE-2022-42970CRITICALA CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a pEPSS 0.7%CVE-2025-43428CRITICALA configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOEPSS 0.7%CVE-2023-29413HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unautheEPSS 0.7%CVE-2021-37697HIGHSensitive information leak in Welcome of tmerc-cogsEPSS 0.7%CVE-2021-37696HIGHSensitive information leak in MassDM of tmerc-cogsEPSS 0.7%CVE-2026-1840HIGHMissing authentication for critical function in Hubbell Aclara Metrum Cellular Web InterfaceEPSS 0.7%CVE-2021-47802HIGHTenda D151 & D301 - Configuration DownloadEPSS 0.7%