Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2024-9137HIGHMoxa Service Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-3281HIGHA vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build EPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2023-25013HIGHAn issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in EPSS 0.5%CVE-2026-65310HIGHMissing authentication and permissive CORS policyEPSS 0.5%CVE-2026-76355HIGHUnauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk EnterpriseEPSS 0.5%CVE-2026-44100HIGHJupiCore charging point reconfiguration without authEPSS 0.5%CVE-2024-52438HIGHWordPress de:branding plugin <= 1.0.2 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-16527HIGHPcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rulesEPSS 0.5%CVE-2024-41969HIGHWAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesEPSS 0.5%CVE-2018-25137HIGHFLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated Config File DisclosureEPSS 0.5%CVE-2026-4649MEDIUMAuth bypass in Apache Artemis allows reading all internal messagesEPSS 0.5%CVE-2024-52437HIGHWordPress Banner System plugin <= 1.0.0 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-2567CRITICALLantronix Xport Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-86480CRITICALIn JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privilegesEPSS 0.5%CVE-2026-67349HIGHOpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin BypassEPSS 0.5%CVE-2026-91996HIGHlamp-cloud through 5.10.0 Missing Authentication for JVM Properties EndpointEPSS 0.5%CVE-2023-34761—An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypassEPSS 0.5%CVE-2026-63647CRITICALCordysCRM SSE Notification Stream Hijack via `/sse/subscribe`EPSS 0.5%