Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-26082CRITICALA file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. EPSS 20.1%CVE-2024-10386CRITICALRockwell Automation FactoryTalk ThinManager Authentication VulnerabilityEPSS 19.3%CVE-2025-58443CRITICALFOG's authentication bypass leads to full SQL DB dumpEPSS 18.5%CVE-2019-5591MEDIUMA Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive informationEPSS 18.4%KEVCVE-2022-45504HIGHAn issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to EPSS 18.3%CVE-2025-61928CRITICALBetter Auth: Unauthenticated API key creation through api-key pluginEPSS 17.9%CVE-2010-5326CRITICALThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows rEPSS 17.8%KEVCVE-2019-6543—AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20EPSS 17.3%CVE-2026-22812HIGHOpenCode's Unauthenticated HTTP Server Allows Arbitrary Command ExecutionEPSS 16.8%CVE-2026-59726CRITICALRuflo: Unauthenticated RCE in MCP bridge default docker-compose deploymentEPSS 16.4%CVE-2020-27986HIGHSonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE:EPSS 16.0%CVE-2021-28809CRITICALMissing Authentication for Critical Function in RTRR Server in HBS3EPSS 15.8%CVE-2024-42455HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserializatEPSS 15.2%CVE-2025-34077CRITICALWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCEEPSS 15.1%CVE-2023-27267CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge)EPSS 14.2%CVE-2025-41656CRITICALPilz: Missing Authentication in Node-RED integrationEPSS 13.8%CVE-2023-41183HIGHNETGEAR Orbi 760 SOAP API Authentication Bypass VulnerabilityEPSS 13.6%CVE-2020-12004—The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and IgnitEPSS 13.6%CVE-2026-36356CRITICALThe GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injecEPSS 13.5%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEV