Weaknesses of type CWE-306

2,611 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-61594CRITICALdjust has an authorization bypass on the WebSocket/SSE mount pathEPSS 0.5%CVE-2022-23862HIGHA Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMEPSS 0.5%CVE-2026-71241HIGHBook-Management-System - Unauthenticated Disclosure of Student PII and Borrowing HistoryEPSS 0.5%CVE-2025-65112CRITICALPubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity SpoofingEPSS 0.5%CVE-2026-69228MEDIUMmissing authentication vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2023-0919HIGHMissing Authentication for Critical Function in kareadita/kavitaEPSS 0.5%CVE-2026-80462CRITICALPrivilege Escalation in Progress Chef AutomateEPSS 0.5%CVE-2026-8364CRITICALGladinet Triofox Missing Authentication for Critical FunctionsEPSS 0.5%CVE-2026-25192CRITICALCTEK Chargeportal Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%CVE-2026-82994CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83261CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is afEPSS 0.5%CVE-2026-70756CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-83000CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83021CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affEPSS 0.5%CVE-2026-83151CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83020CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83462CRITICALVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.5%CVE-2026-83232CRITICALVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versiEPSS 0.5%CVE-2026-73961CRITICALVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.5%