Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-27259HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2026-60253CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60244CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-63429HIGHHeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextEPSS 0.5%CVE-2024-27758HIGHIn RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(cEPSS 0.5%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.5%CVE-2026-67426CRITICALFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationEPSS 0.5%CVE-2023-4884MEDIUMMultiple vulnerabilities in Open5GSEPSS 0.5%CVE-2026-65319HIGHFeedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/textEPSS 0.5%CVE-2026-55571HIGHdjust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler callsEPSS 0.5%CVE-2026-27449HIGHUmbraco.Engage.Forms Allows Unauthorized Access to Multiple API EndpointsEPSS 0.5%CVE-2022-32503HIGHAn issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect toEPSS 0.5%CVE-2026-15978HIGHCVE-2026-15978EPSS 0.5%CVE-2026-89250HIGHWWBN AVideo Unauthenticated File Read via getRecordedFile.phpEPSS 0.5%CVE-2025-25060HIGHMissing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server whEPSS 0.5%CVE-2026-80234MEDIUMCAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing AuthenticationEPSS 0.5%CVE-2024-10776HIGHSICK InspectorP61x and SICK InspectorP62x: missing authenticationEPSS 0.5%CVE-2026-9202CRITICALUnauthenticated User Registration Could Lead to Remote Code ExecutionEPSS 0.5%CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2023-51062MEDIUMAn unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers toEPSS 0.5%