Weaknesses of type CWE-306

2,609 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-84075CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2021-47933CRITICALWordPress MStore API 2.0.6 Arbitrary File UploadEPSS 0.6%CVE-2024-6422CRITICALPepperl+Fuchs: OIT Products can be manipulated via unintended Telnet accessEPSS 0.6%CVE-2024-6981CRITICALOMNTEC Proteus Tank Monitoring Missing Authentication for Critical FunctionEPSS 0.6%CVE-2022-41271CRITICALAn unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PEPSS 0.6%CVE-2026-32064HIGHOpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC ObserverEPSS 0.6%CVE-2026-69703CRITICALAtlas-Livre Unauthenticated Access via Admin Controllers Missing ExitEPSS 0.6%CVE-2026-88263HIGHXikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration datEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.6%CVE-2026-34731HIGHAVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.phpEPSS 0.6%CVE-2026-92729HIGHSigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics EndpointsEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2022-20861CRITICALCisco Nexus Dashboard Unauthorized Access VulnerabilitiesEPSS 0.6%CVE-2023-6221HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-25848CRITICALIn JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possibleEPSS 0.6%CVE-2026-54061CRITICALDgraph Alpha group stores can be replaced via unauthenticated external snapshot importEPSS 0.6%CVE-2026-8602HIGHMissing authentication for critical function in ScadaBREPSS 0.6%CVE-2020-5589—SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SPEPSS 0.6%CVE-2026-84700HIGHPika Unauthenticated Replication Access via Internal Protobuf PortEPSS 0.6%