Weaknesses of type CWE-306

2,600 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-71327CRITICALFlowise - Authentication Bypass via Unprotected Registration EndpointEPSS 0.7%CVE-2026-73666HIGHOpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/deleteEPSS 0.7%CVE-2025-7897MEDIUMharry0703 MoneyPrinterTurbo API Endpoint base.py verify_token missing authenticationEPSS 0.7%CVE-2026-8737MEDIUMSanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authenticationEPSS 0.7%CVE-2026-76639HIGHUnitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path TraversalEPSS 0.7%CVE-2024-9644CRITICALFour-Faith F3x36 bapply.cgi Auth BypassEPSS 0.7%CVE-2025-34069CRITICALGFI Kerio Control GFIAgent Authentication Bypass via Proxy ForwardingEPSS 0.7%CVE-2022-44216HIGHGnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's originEPSS 0.7%CVE-2022-4980CRITICALGeneral Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin PageEPSS 0.7%CVE-2025-59695CRITICALEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user EPSS 0.7%CVE-2026-62241CRITICALclawvet < 0.7.5 Hard-coded JWT Secret Session ForgeryEPSS 0.7%CVE-2026-82787HIGHMissing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product maEPSS 0.7%CVE-2023-51571HIGHVoltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service VulnerabilityEPSS 0.7%CVE-2026-29796CRITICALIGL-Technologies eParking.fi Missing Authentication for Critical FunctionEPSS 0.7%CVE-2025-21515HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.7%CVE-2026-5724MEDIUMMissing Authentication on Streaming gRPC Replication EndpointEPSS 0.7%CVE-2026-55678MEDIUMArc: Unauthenticated cluster node admission when `cluster.shared_secret` is unsetEPSS 0.7%CVE-2025-34207HIGHVasion Print (formerly PrinterLogic) Insecure SSH Client ConfigurationEPSS 0.7%CVE-2026-0611CRITICALSpacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET RemotingEPSS 0.7%CVE-2021-36779CRITICALHost operations allowed in privileged Longhorn managed podsEPSS 0.7%