Weaknesses of type CWE-306

2,599 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-35277HIGHA missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.EPSS 0.7%CVE-2026-13164HIGHUnauthenticated self-registration in MailerUp allows access to stored email dataEPSS 0.7%CVE-2026-73173HIGHNozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol oEPSS 0.7%CVE-2023-0052CRITICALSAUTER Controls Nova 200–220 Series Missing Authentication for Critical FunctionEPSS 0.7%CVE-2025-30410CRITICALSensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud AEPSS 0.7%CVE-2026-11420CRITICALPath Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File ReadEPSS 0.7%CVE-2026-16209MEDIUMGerapy Project Upload Endpoint views.py missing authenticationEPSS 0.7%CVE-2024-3777CRITICALAi3 QbiBot - Broken Access ControlEPSS 0.7%CVE-2023-22804CRITICALCVE-2023-22804EPSS 0.7%CVE-2025-63389CRITICALA critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The plaEPSS 0.7%CVE-2026-9141CRITICALTaiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web InterfaceEPSS 0.7%CVE-2026-53985HIGHGround Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IOEPSS 0.7%CVE-2017-20222HIGHTelesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote RebootEPSS 0.7%CVE-2026-81475HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An EPSS 0.7%CVE-2022-43976CRITICALAn issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API iEPSS 0.7%CVE-2026-85663CRITICALAim 3.29.1 Remote Code Execution via Unauthenticated Method DispatchEPSS 0.7%CVE-2025-4019MEDIUM20120630 Novel-Plus GeneratorController.java genCode missing authenticationEPSS 0.7%CVE-2026-63765HIGHChatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob CreationEPSS 0.7%CVE-2026-58446MEDIUMPresenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP EndpointEPSS 0.7%CVE-2022-30515MEDIUMZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enuEPSS 0.7%