Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-20357CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.6%CVE-2026-56346MEDIUMAVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php EndpointEPSS 0.6%CVE-2023-54352CRITICALWordPress Seotheme Remote Code Execution UnauthenticatedEPSS 0.6%CVE-2026-14976HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerabilityEPSS 0.6%CVE-2026-69091HIGHAdmidio before 5.0.11 Authentication Bypass via forum.phpEPSS 0.6%CVE-2026-84485HIGHAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search EndpointEPSS 0.6%CVE-2026-62422CRITICALIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass vEPSS 0.6%CVE-2026-50242CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via diEPSS 0.6%CVE-2026-13007HIGHInsecure Public Caching on REST API Endpoints in Tenable Identity ExposureEPSS 0.6%CVE-2026-72688HIGHOpenSignLabs opensignserver - Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-77254CRITICALMCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentialsEPSS 0.6%CVE-2026-81094CRITICALmcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring AuthenticationEPSS 0.6%CVE-2023-22650HIGHRancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderEPSS 0.6%CVE-2026-4767CRITICALImproper Access Control in TR7's WAF-ASPEPSS 0.6%CVE-2026-44321HIGHfree5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)EPSS 0.6%CVE-2022-35136MEDIUMBoodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.EPSS 0.6%CVE-2026-75329CRITICALThe Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can dirEPSS 0.6%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.6%CVE-2025-5906MEDIUMcode-projects Laundry System data missing authenticationEPSS 0.6%CVE-2023-5881HIGHUnauthenticated access permitted to web interface page "Garage Door Control Module Setup"EPSS 0.6%