Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-34232MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via Lexmark dellCheck.phpEPSS 0.6%CVE-2022-43761CRITICALLack of authentication when managing APROL databaseEPSS 0.6%CVE-2026-78480HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.6%CVE-2025-40664CRITICALMissing authentication vulnerability in TCMAN GIM v11EPSS 0.5%CVE-2026-14525CRITICALIBM WebSphere Application Server Liberty is affected by an authenication bypassEPSS 0.5%CVE-2023-54344CRITICALEclipse Equinox OSGi 3.7.2 Remote Code Execution via ConsoleEPSS 0.5%CVE-2026-33366MEDIUMMissing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the proEPSS 0.5%CVE-2024-42462CRITICALBypass multifactor authenticationEPSS 0.5%CVE-2023-3104MEDIUMMissing Authentication for Critical Function in Unitree Robotics A1EPSS 0.5%CVE-2026-4436HIGHGPL Odorizers GPL750 Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-75919MEDIUMphpMyFAQ before 4.1.7 Authentication Bypass via Setup APIEPSS 0.5%CVE-2026-60372CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-1837HIGHMissing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affEPSS 0.5%CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2024-8530MEDIUMCWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generatEPSS 0.5%CVE-2026-60366CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-24934MEDIUMMicrosoft Defender Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-42017CRITICALAn issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenarEPSS 0.5%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.5%CVE-2026-1453CRITICALMissing Authentication for Critical Function in KiloView Encoder SeriesEPSS 0.5%