Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-41793HIGHA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an enEPSS 0.5%CVE-2019-25227HIGHTellion HN-2204AP Unauthenticated Configuration DisclosureEPSS 0.5%CVE-2025-11529MEDIUMChurchCRM API Endpoint AuthMiddleware.php AuthMiddleware missing authenticationEPSS 0.5%CVE-2025-45814CRITICALMissing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attacEPSS 0.5%CVE-2025-30727CRITICALVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected EPSS 0.5%CVE-2024-48882HIGHA denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pEPSS 0.5%CVE-2023-37373MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file writeEPSS 0.5%CVE-2025-23417HIGHA denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted EPSS 0.5%CVE-2026-33951MEDIUMsignalk-server: Unauthenticated Source Priorities ManipulationEPSS 0.5%CVE-2024-56799CRITICALSimofa Allows Unauthenticated Access to API RoutesEPSS 0.5%CVE-2026-31240HIGHThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as upEPSS 0.5%CVE-2025-62582CRITICALDIAView - Authentication Bypass VulnerabilityEPSS 0.5%CVE-2025-7328CRITICALRockwell Automation Comms - 1783-NATR Multiple Broken Authentication VulnerabilitiesEPSS 0.5%CVE-2024-12869MEDIUMImproper Authentication in infiniflow/ragflowEPSS 0.5%CVE-2026-56286HIGHCapgo - Account Deletion Without Password ConfirmationEPSS 0.5%CVE-2026-44328HIGHfree5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutatingEPSS 0.5%CVE-2024-50381HIGHMissing Authentication for Critical Function in Snap One OVRC cloudEPSS 0.5%CVE-2026-14952HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authenticationEPSS 0.5%CVE-2026-41899MEDIUMCoolify unauthenticated feedback endpoint allows Discord webhook abuseEPSS 0.5%CVE-2026-67578HIGHFA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the EPSS 0.5%