Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-9994CRITICALAmp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not require authenticationEPSS 0.5%CVE-2026-14446CRITICALIBM WebSphere Application Server is affected by a privilege escalationEPSS 0.5%CVE-2026-1341CRITICALMissing Authentication for Critical Function in Avation Light Engine ProEPSS 0.5%CVE-2026-30933HIGHFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/infoEPSS 0.5%CVE-2024-39601HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1EPSS 0.5%CVE-2024-12757HIGHNedap Librix Ecoreader Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-23944HIGHArcane allows unauthenticated proxy access to remote environmentsEPSS 0.5%CVE-2026-48814CRITICALNetwork-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)EPSS 0.5%CVE-2020-22661MEDIUMIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.5%CVE-2026-40289CRITICALPraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessionsEPSS 0.5%CVE-2026-33038HIGHAVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deploymentsEPSS 0.5%CVE-2026-63101HIGHOpen Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export EndpointEPSS 0.5%CVE-2026-3323HIGHVEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devicesEPSS 0.5%CVE-2026-75133HIGHKeep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_processEPSS 0.5%CVE-2026-88259HIGHCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-23783HIGHImproper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows aEPSS 0.5%CVE-2025-8861CRITICALChanging|TSA - Missing AuthenticationEPSS 0.5%CVE-2025-34222CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Admin APIs Used to Modify SSL CertificatesEPSS 0.5%CVE-2021-47731CRITICALSelea Targa IP Camera Developer Backdoor Configuration OverwriteEPSS 0.5%CVE-2024-48768HIGHAn issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmwaEPSS 0.5%