Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2021-32930—The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and eEPSS 8.1%CVE-2025-52089HIGHA hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to exEPSS 8.0%CVE-2024-21006HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 7.9%CVE-2025-59246CRITICALAzure Entra ID Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2023-7308HIGHSecGate3600 Firewall Information Disclosure via authManageSet.cgiEPSS 7.5%CVE-2015-10141CRITICALXdebug Remote Debugger Unauthenticated OS Command ExecutionEPSS 7.4%CVE-2023-37265CRITICALIncorrect identification of source IP addresses in CasaOSEPSS 7.4%CVE-2025-24865CRITICALmySCADA myPRO Manager Missing Authentication for Critical FunctionEPSS 7.2%CVE-2025-55583CRITICALD-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi EPSS 7.0%CVE-2024-32735CRITICALCyberPower PowerPanel Enterprise Missing AuthenticationEPSS 6.8%CVE-2026-62241CRITICALclawvet < 0.7.5 Hard-coded JWT Secret Session ForgeryEPSS 6.5%CVE-2025-52692HIGHBypass AuthenticationEPSS 6.4%CVE-2022-46463HIGHAn access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. EPSS 6.2%CVE-2024-57725MEDIUMAn issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication,EPSS 6.2%CVE-2025-34103CRITICALWePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgiEPSS 6.0%CVE-2024-5721HIGHLogsign Unified SecOps Platform Missing Authentication Remote Code Execution VulnerabilityEPSS 6.0%CVE-2017-3184—ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory EPSS 5.9%CVE-2024-21306MEDIUMMicrosoft Bluetooth Driver Spoofing VulnerabilityEPSS 5.8%CVE-2023-54335CRITICALeXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)EPSS 5.8%CVE-2025-14346CRITICALWHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within ranEPSS 5.6%