Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-97878MEDIUMzhistaredu StarTraining Druid Console index.html anonymous missing authenticationEPSS 0.6%CVE-2025-53938MEDIUMWeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpointsEPSS 0.6%CVE-2024-45276HIGHMB connect line/Helmholz: tmp directory exposed via webserviceEPSS 0.6%CVE-2025-13510CRITICALIskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiyEPSS 0.6%CVE-2021-32709MEDIUMCreation of order credits was not validated by acl in admin ordersEPSS 0.6%CVE-2023-22072CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected EPSS 0.6%CVE-2022-3738MEDIUMWAGO: Missing authentication for config export functionality in multiple productsEPSS 0.6%CVE-2024-35293CRITICALSchneider Elektronik Series 700 prone to missing authentication for critical reset functionEPSS 0.6%CVE-2026-58574CRITICALDell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to thEPSS 0.6%CVE-2022-45433LOWSome Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall acEPSS 0.6%CVE-2023-30744HIGHImproper access control during application start-up in SAP AS NetWeaver JAVA.EPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2024-12511HIGHSMB/FTP Address Book Scan Pass-back attackEPSS 0.6%CVE-2026-45327HIGHTinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injectionEPSS 0.6%CVE-2026-50085HIGHAqara Board IoT insecure debug APIEPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%CVE-2026-82266CRITICALRedpanda Admin API Unauthenticated Superuser Access via Default ConfigurationEPSS 0.6%CVE-2026-34162CRITICALFastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key TheftEPSS 0.6%CVE-2026-54446HIGHNetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP ModeEPSS 0.6%CVE-2024-45049HIGHNix Hydra Missing authentication when triggering evaluationsEPSS 0.6%