Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-19875HIGHUnauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in LangflowEPSS 0.5%CVE-2025-7114MEDIUMSimStudioAI sim Session route.ts POST missing authenticationEPSS 0.5%CVE-2025-70147HIGHMissing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackersEPSS 0.5%CVE-2026-19426HIGHFitSoft|POS Sytstem - Missing AuthenticationEPSS 0.5%CVE-2026-73669MEDIUMSignify Philips Hue Bridge Pro MQTT broker missing authenticationEPSS 0.5%CVE-2026-34952CRITICALPraisonAI: Missing Authentication in WebSocket GatewayEPSS 0.5%CVE-2023-21856HIGHVulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versEPSS 0.5%CVE-2025-4557HIGHZONG YU Parking Management System - Missing AuthenticationEPSS 0.5%CVE-2022-24396—The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be aEPSS 0.5%CVE-2026-12691HIGHAuthentication Bypass in Vimesoft's Enterprise Video PlatformEPSS 0.5%CVE-2018-25335CRITICALWordPress Plugin Peugeot Music 1.0 Arbitrary File UploadEPSS 0.5%CVE-2022-31701MEDIUMVMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this isEPSS 0.5%CVE-2025-3232HIGHMitsubishi Electric Europe smartRTU Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-21272HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0EPSS 0.5%CVE-2026-86801HIGHTo Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload HandlerEPSS 0.5%CVE-2023-53969CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password ChangeEPSS 0.5%CVE-2024-47902MEDIUMA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 0.5%CVE-2023-53967CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password ChangeEPSS 0.5%CVE-2025-5192CRITICALSoar Cloud HRD Human Resource Management System - Missing Authentication for Critical FunctionEPSS 0.5%CVE-2023-53970HIGHScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board ConfigEPSS 0.5%