Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2021-4468HIGHPLANEX CS-QP50F-ING2 Smart Camera Remote Configuration DisclosureEPSS 0.7%CVE-2026-31071CRITICALAPI endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers caEPSS 0.7%CVE-2024-21007HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.7%CVE-2024-3279CRITICALImproper Access Control in mintplex-labs/anything-llmEPSS 0.6%CVE-2020-36871HIGHESCAM QD-900 Unauthenticated Configuration DisclosureEPSS 0.6%CVE-2025-53378HIGHA missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticaEPSS 0.6%CVE-2025-12003HIGHA path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of thEPSS 0.6%CVE-2025-9254CRITICALUniong|WebITR - Missing AuthenticationEPSS 0.6%CVE-2026-62645CRITICALA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be usEPSS 0.6%CVE-2025-8610CRITICALAOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-40702CRITICALEVoke Systems EVoke CSMS Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-97879MEDIUMzhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authenticationEPSS 0.6%CVE-2025-8611CRITICALAOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-53072CRITICALVulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that areEPSS 0.6%CVE-2026-40884CRITICALgoshs: Empty-username SFTP password authentication bypass in goshsEPSS 0.6%CVE-2026-27012CRITICALUnauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.phpEPSS 0.6%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.6%CVE-2025-10452CRITICALGotac|Statistical Database System - Missing AuthenticationEPSS 0.6%CVE-2022-34908HIGHAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some fEPSS 0.6%CVE-2026-21446HIGHBagisto Missing Authentication on Installer API EndpointsEPSS 0.6%