Weaknesses of type CWE-306

2,607 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-5632MEDIUMassafelovic gpt-researcher HTTP REST API Endpoint missing authenticationEPSS 0.7%CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-15491MEDIUMRafyMrX TOKO-ONLINE-ROTI missing authenticationEPSS 0.7%CVE-2026-82919MEDIUMcu silicon edit Endpoint views.py create_app missing authenticationEPSS 0.7%CVE-2026-90579MEDIUMcheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authenticationEPSS 0.7%CVE-2026-18810MEDIUMH3C NX15 networkSetup missing authenticationEPSS 0.7%CVE-2026-6582MEDIUMTransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authenticationEPSS 0.7%CVE-2026-13546MEDIUMFeehi CMS REST API Endpoint articles missing authenticationEPSS 0.7%CVE-2026-7042MEDIUM666ghj MiroFish REST API Endpoint __init__.py create_app missing authenticationEPSS 0.7%CVE-2026-6577MEDIUMliangliangyy DjangoBlog logtracks Endpoint views.py missing authenticationEPSS 0.7%CVE-2026-6129MEDIUMzhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authenticationEPSS 0.7%CVE-2026-4562MEDIUMMacCMS Timming API Endpoint Timming.php weak authenticationEPSS 0.7%CVE-2026-5000MEDIUMPromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authenticationEPSS 0.7%CVE-2026-93559MEDIUMForget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authenticationEPSS 0.7%CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-45083CRITICALGoobi viewer: Unauthenticated Solr Streaming Expression ProxyEPSS 0.7%CVE-2022-29877—A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.0EPSS 0.7%CVE-2026-4640HIGHGalaxy Software Services|Vitals ESP - Missing AuthenticationEPSS 0.7%CVE-2021-4468HIGHPLANEX CS-QP50F-ING2 Smart Camera Remote Configuration DisclosureEPSS 0.7%CVE-2026-31071CRITICALAPI endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers caEPSS 0.7%