Weaknesses of type CWE-306

2,611 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-83000CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83462CRITICALVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.5%CVE-2026-83232CRITICALVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versiEPSS 0.5%CVE-2026-70748CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-71214CRITICALNASA-AMMOS plandev - Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-serverEPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%CVE-2026-82995CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83020CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-73961CRITICALVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.5%CVE-2026-83021CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affEPSS 0.5%CVE-2026-73843CRITICALOpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsEPSS 0.5%CVE-2026-40461HIGHAnviz Products Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-39300HIGHMissing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is eEPSS 0.5%CVE-2026-67610HIGHOpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR AccessEPSS 0.5%CVE-2025-48469CRITICALUnauthenticated Firmware UploadEPSS 0.5%CVE-2017-20213HIGHFLIR Thermal Camera F/FC/PT/D Stream 8.0.0.64 Unauthenticated Stream DisclosureEPSS 0.5%CVE-2026-49254LOWDragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauthEPSS 0.5%CVE-2024-21654MEDIUMrubygems.org MFA Bypass through password reset function could allow account takeover EPSS 0.5%CVE-2025-6678HIGHAutel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-53981HIGHCap-go < v12.128.2 Account Takeover via Unauthenticated Email Change MechanismEPSS 0.5%