Weaknesses of type CWE-306

2,609 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-34200HIGHNhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network PortEPSS 0.6%CVE-2026-51937HIGHAn issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.javEPSS 0.6%CVE-2026-73246HIGHKestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentialsEPSS 0.6%CVE-2021-4461CRITICALSeeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication BypassEPSS 0.6%CVE-2026-82641HIGHKeploy 3.1.0-3.6.25 Unauthenticated TLS Key ExposureEPSS 0.6%CVE-2026-67966CRITICALTenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shEPSS 0.6%CVE-2024-1573MEDIUMMissing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.EPSS 0.6%CVE-2023-2187MEDIUMOn Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WeEPSS 0.6%CVE-2023-49115HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-38059HIGHST Engineering iDirect iQ-Series Terminals Missing authentication for critical functionEPSS 0.6%CVE-2026-2165MEDIUMdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2023-22803HIGHCVE-2023-22803EPSS 0.6%CVE-2025-8558LOWInsider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated uEPSS 0.6%CVE-2024-32752HIGHJohnson Controls Software House iSTAR Configuration Utility (ICU) ToolEPSS 0.6%CVE-2024-41988CRITICALMissing Authentication for Critical Function vulnerability in TEM Opera Plus FM Family TransmitterEPSS 0.6%CVE-2026-65014MEDIUMn8n before 2.28.0 Authentication Bypass via test-webhookEPSS 0.6%CVE-2026-62325CRITICALgoshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)EPSS 0.6%CVE-2026-59808HIGHAVideo Authentication Bypass via Unkeyed Video Hash DisclosureEPSS 0.6%CVE-2026-84075CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%