Weaknesses of type CWE-306

2,608 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-25071HIGHXikeStor SKS8310-8X switch_config.src Missing AuthenticationEPSS 0.5%CVE-2023-22101HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-58473CRITICALCognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settingsEPSS 0.5%CVE-2018-25136HIGHFLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2025-15620CRITICALHiOS Switch Platform Denial-of-Service via Web InterfaceEPSS 0.5%CVE-2024-54983CRITICALAn issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.EPSS 0.5%CVE-2026-26319HIGHOpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated RequestsEPSS 0.5%CVE-2024-54984CRITICALAn issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the EPSS 0.5%CVE-2026-88285CRITICALGV-LPC2011/LPC2211 - Unauthenticated PTZ Control ServiceEPSS 0.5%CVE-2025-27935HIGHAuthentication Bypass in OTP (One-time Passcode) IdP Adapter Integration KitEPSS 0.5%CVE-2024-45229MEDIUMThe Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, andEPSS 0.5%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.5%CVE-2020-7479—A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), EPSS 0.5%CVE-2026-88065HIGH`tts-be` application has a Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-53469CRITICALMigration-planner: unprotected delete endpoint wipes all tenant dataEPSS 0.5%CVE-2026-61233CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported EPSS 0.5%CVE-2026-60289CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60240CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60288CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60253CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%