Weaknesses of type CWE-306

2,610 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2022-50591HIGHAdvantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2026-63647CRITICALCordysCRM SSE Notification Stream Hijack via `/sse/subscribe`EPSS 0.5%CVE-2026-55884CRITICALTilt: Missing authentication on the network-exposed Tilt HUD serverEPSS 0.5%CVE-2023-34761—An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypassEPSS 0.5%CVE-2026-34758CRITICALOneUptime: Missing Authentication on Notification EndpointsEPSS 0.5%CVE-2026-28450HIGHOpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP EndpointsEPSS 0.5%CVE-2026-25791HIGHSliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of ServiceEPSS 0.5%CVE-2026-92717CRITICALCovenant through 0.6 Missing Authentication on the CovenantHub SignalR HubEPSS 0.5%CVE-2026-61155CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2026-46910CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). SupportedEPSS 0.5%CVE-2026-61130CRITICALVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.5%CVE-2026-33719HIGHAVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.phpEPSS 0.5%CVE-2022-0878MEDIUMNovel attack against the Combined Charging System (CCS) in electric vehicles to remotely cause a denial of serviceEPSS 0.5%CVE-2026-47040CRITICALVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.EPSS 0.5%CVE-2026-25878MEDIUMFroshAdminer Adminer UI is accessible without admin sessionEPSS 0.5%CVE-2026-1632CRITICALRISS SRL MOMA Seismic Station Missing Authentication for Critical FunctionEPSS 0.5%CVE-2025-41715CRITICALMissing Authentication for Database Access in Web ApplicationEPSS 0.5%CVE-2024-22415HIGHUnsecured endpoints in the jupyter-lsp server extensionEPSS 0.5%CVE-2024-4428MEDIUMSensetive Data Exposure in Menulux Managment PortalEPSS 0.5%CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%