Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2024-8456CRITICALPLANET Technology switch devices - Missing Authentication for multiple HTTP routesEPSS 0.6%CVE-2021-32700CRITICALSupply chain attack via MiTM against usersEPSS 0.6%CVE-2026-1364CRITICALJNC|IAQS and I6 - Missing AuthenticationEPSS 0.6%CVE-2024-7940HIGHThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.6%CVE-2025-32440CRITICALNetAlertX Vulnerable to Authentication BypassEPSS 0.6%CVE-2026-24731CRITICALEV2GO ev2go.io Missing Authentication for Critical FunctionEPSS 0.6%CVE-2023-24526MEDIUMImproper Access Control in SAP NetWeaver AS Java (Classload Service)EPSS 0.6%CVE-2026-93960MEDIUMPixelfed OAuth Scope ApiV1Controller.php instancePeers missing authenticationEPSS 0.6%CVE-2025-25224MEDIUMThe LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerabilityEPSS 0.6%CVE-2026-3356CRITICALMissing Authentication for Critical Function vulnerability in Anritsu Remote Spectrum MonitorEPSS 0.6%CVE-2023-40393HIGHAn authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Photos iEPSS 0.6%CVE-2023-35872MEDIUMMissing Authentication check in SAP NetWeaver Process Integration (Message Display Tool)EPSS 0.6%CVE-2026-33203HIGHSiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive BypassEPSS 0.6%CVE-2023-35873MEDIUMMissing Authentication check in SAP NetWeaver Process Integration (Runtime Workbench)EPSS 0.6%CVE-2026-48911HIGHApache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation FlowEPSS 0.6%CVE-2025-4555CRITICALZONG YU Okcat Parking Management Platform - Missing AuthenticationEPSS 0.6%CVE-2026-82906MEDIUMsdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authenticationEPSS 0.6%CVE-2026-34160HIGHChamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata servicesEPSS 0.6%CVE-2023-44152MEDIUMSensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber ProtectEPSS 0.6%