Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-11661MEDIUMProjectsAndPrograms School Management System missing authenticationEPSS 0.5%CVE-2026-22096CRITICALMissing authentication for webserver endpointsEPSS 0.5%CVE-2026-44895CRITICALGitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab toolsEPSS 0.5%CVE-2025-8284CRITICALPacket Power EMX and EG Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-1453CRITICALMissing Authentication for Critical Function in KiloView Encoder SeriesEPSS 0.5%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.5%CVE-2026-54309HIGHn8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control SessionsEPSS 0.5%CVE-2022-41776HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration methoEPSS 0.5%CVE-2023-41367MEDIUMMissing Authentication check in SAP NetWeaver (Guided Procedures)EPSS 0.5%CVE-2026-50287HIGHMissing Authentication for Critical Function in @agenticmail/mcpEPSS 0.5%CVE-2026-12819CRITICALDVP-12SE Missing Authentication and Unauthorized Write access VulnerabilityEPSS 0.5%CVE-2026-42856HIGHNetwork-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool callsEPSS 0.5%CVE-2026-90449MEDIUMWhen a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface EPSS 0.5%CVE-2026-45044HIGHRustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlersEPSS 0.5%CVE-2026-47136MEDIUMRustFS: Unauthenticated RustFS console license endpoint exposes license metadataEPSS 0.5%CVE-2025-63958CRITICALMILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authEPSS 0.5%CVE-2026-73673HIGHNetis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware AuthenticationEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.5%CVE-2026-9152CRITICALUnauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index DestructionEPSS 0.5%CVE-2024-41793HIGHA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an enEPSS 0.5%