Weaknesses of type CWE-306

2,600 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-26575HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2025-61956CRITICALMissing Authentication for Critical Function in Radiometrics VizAirEPSS 0.7%CVE-2022-45432MEDIUMSome Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy,EPSS 0.7%CVE-2024-49052HIGHMicrosoft Azure PolicyWatch Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-54460CRITICALOpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeoverEPSS 0.7%CVE-2026-24789CRITICALZLAN Information Technology ZLAN5143D Missing Authentication for Critical FunctionEPSS 0.7%CVE-2023-50199HIGHD-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-26576HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2023-27376HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2023-27375HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2023-26570HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2023-27257HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2024-48966CRITICALLife2000 service tools for test and calibration do not support user authenticationEPSS 0.7%CVE-2023-26574HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2023-27377HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2026-85667CRITICALxiaobei through 5.5.2 Unauthenticated Webhook Message InjectionEPSS 0.7%CVE-2026-48989HIGHWindows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORSEPSS 0.7%CVE-2026-84423MEDIUMCasdoor upload-resource API resource.go missing authenticationEPSS 0.7%CVE-2026-81202MEDIUMitsourcecode Payroll System CRUD Operation ajax.php delete missing authenticationEPSS 0.7%CVE-2026-5616MEDIUMJeecgBoot AI Chat JeecgBizToolsProvider.java missing authenticationEPSS 0.7%