Weaknesses of type CWE-306

2,600 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-41688CRITICAL Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify useEPSS 0.7%CVE-2025-9983HIGHLack of Authentication for RTSP streamEPSS 0.7%CVE-2026-71289CRITICALNASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST APIEPSS 0.7%CVE-2022-24190HIGHThe /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is nEPSS 0.7%CVE-2026-2577CRITICALNanobot Unauthenticated WhatsApp Session Hijack via WebSocket BridgeEPSS 0.7%CVE-2022-21691MEDIUMImproper Access Control in OnionshareEPSS 0.7%CVE-2026-32646HIGHGardyn Cloud API Missing Authentication for Critical FunctionEPSS 0.7%CVE-2022-45424MEDIUMSome Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key byEPSS 0.7%CVE-2023-1083CRITICALWelotec: improper access control in TK500v1 router seriesEPSS 0.7%CVE-2023-43644CRITICALImproper authentication in the SOCKS5 inbound in sing-boxEPSS 0.7%CVE-2026-61613HIGHCursor: Cloud Agent Browser Sandbox EscapeEPSS 0.7%CVE-2026-4187MEDIUMTiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authenticationEPSS 0.7%CVE-2026-65941HIGHWhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.EPSS 0.7%CVE-2025-66555HIGHAirKeyboard iOS App 1.0.5 - Remote Input InjectionEPSS 0.7%CVE-2024-8584CRITICALLEARNING DIGITAL Orca HCM - Missing AuthenticationEPSS 0.7%CVE-2025-15681CRITICALInsufficient Webserver AuthenticationEPSS 0.7%CVE-2026-26288CRITICALEveron api.everon.io Missing Authentication for Critical FunctionEPSS 0.7%CVE-2026-50759HIGHAn issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endEPSS 0.7%CVE-2025-71327CRITICALFlowise - Authentication Bypass via Unprotected Registration EndpointEPSS 0.7%CVE-2026-94151MEDIUMOmega Solution HRM OS Role Permission API permission missing authenticationEPSS 0.7%