Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-79954HIGHNASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCIDEPSS 0.6%CVE-2025-46275CRITICALPlanet Technology Network Products Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-49357HIGHStreamable HTTP mode exposes LINE Desktop read/send tools without MCP authenticationEPSS 0.6%CVE-2026-44329CRITICALfree5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlersEPSS 0.6%CVE-2024-45438CRITICALAn issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.phEPSS 0.6%CVE-2023-22087HIGHVulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported veEPSS 0.6%CVE-2026-6376HIGHMissing authentication for critical function in SpiceJet Online Booking SystemEPSS 0.6%CVE-2026-68953HIGHMissing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product LineupsEPSS 0.6%CVE-2026-92808CRITICALServer-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System CompromiseEPSS 0.6%CVE-2025-65824HIGHAn unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using BlEPSS 0.6%CVE-2022-50981CRITICALMultiple Innomic VibroLine VLX HD 5.0 and avibia AVLX weak password requirementsEPSS 0.6%CVE-2025-26366HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2025-26362HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2025-26365HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2025-26363HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2023-27256MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.6%CVE-2025-26364HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2026-27584CRITICALActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpointsEPSS 0.6%CVE-2019-25632MEDIUMphpFileManager 1.7.8 Local File Inclusion via index.phpEPSS 0.6%CVE-2025-29870HIGHMissing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticaEPSS 0.6%