Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-5716CRITICALASUS Armoury Crate - Arbitrary File WriteEPSS 0.6%CVE-2023-38422HIGHWalchem Intuition Missing Authentication for Critical Function EPSS 0.6%CVE-2023-21979HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.6%CVE-2026-58375HIGHJimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/exportEPSS 0.6%CVE-2026-72586HIGHfrangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event HandlerEPSS 0.6%CVE-2026-35064HIGHSenseLive X3050 Missing authentication for critical functionEPSS 0.6%CVE-2026-92720CRITICALKubero through 3.1.1 Unauthenticated Notifications API AccessEPSS 0.6%CVE-2026-85701MEDIUMramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authenticationEPSS 0.6%CVE-2026-28472CRITICALOpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect HandshakeEPSS 0.6%CVE-2022-50595CRITICALAdvantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCEEPSS 0.6%CVE-2022-50592CRITICALAdvantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCEEPSS 0.6%CVE-2026-14162CRITICALAdvantech|Hospital Quering Management - Missing AuthenticationEPSS 0.6%CVE-2026-71262CRITICALIoTSharp BlobStorageController Missing Authentication and Path TraversalEPSS 0.6%CVE-2023-28470MEDIUMIn Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.EPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%CVE-2025-58083CRITICALGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-71319CRITICALNuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionEPSS 0.6%CVE-2022-41629HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, whichEPSS 0.6%CVE-2021-4469HIGHDenver SHO-110 IP Camera Unauthenticated Snapshot AccessEPSS 0.6%CVE-2026-19749MEDIUMTenda CH7 RTSP/ONVIF missing authenticationEPSS 0.6%