Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-63206CRITICALAn authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing atEPSS 0.5%CVE-2024-0949CRITICALImproper Access Control in Talya Informatics' ElektrawebEPSS 0.5%CVE-2023-54350HIGHWordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedEPSS 0.5%CVE-2025-34230MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via HP log_off_single_sign_on.phpEPSS 0.5%CVE-2018-25139HIGHFLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2025-34229MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via HP installApp.phpEPSS 0.5%CVE-2023-4857HIGH An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI caEPSS 0.5%CVE-2023-53773HIGHMiniDVBLinux 5.4 Unauthenticated Live Stream Disclosure via tv_action.shEPSS 0.5%CVE-2019-25226HIGHDongyoung Media DM-AP240T/W Unauthenticated Configuration DisclosureEPSS 0.5%CVE-2026-44327CRITICALfree5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerEPSS 0.5%CVE-2026-86727HIGHAVideo through 29.0 Information Disclosure via stats.json.phpEPSS 0.5%CVE-2025-34331HIGHAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Read via download.phpEPSS 0.5%CVE-2025-40771CRITICALA vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6EPSS 0.5%CVE-2026-20781CRITICALCloudCharge cloudcharge.se Missing Authentication for Critical FunctionEPSS 0.5%CVE-2022-4240MEDIUMUnauthenticated API allowing an attacker to obtain the information about network resourcesEPSS 0.5%CVE-2023-53974HIGHD-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated RequestEPSS 0.5%CVE-2026-1023HIGHGotac|Statistics Database System - Missing AuthenticationEPSS 0.5%CVE-2023-27261MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2023-26579MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2026-14529CRITICALIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgeryEPSS 0.5%