Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-34073CRITICALstamparm/maltrail <=0.54 Remote Command ExecutionEPSS 5.6%CVE-2026-3611CRITICALHoneywell IQ4x BMS Controller Missing authentication for critical functionEPSS 5.5%CVE-2026-67208CRITICALJuggle 1.6.0 Unauthenticated RCE via Exposed H2 ConsoleEPSS 5.3%CVE-2020-15798CRITICALA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP MoEPSS 5.2%CVE-2017-3216—WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remoteEPSS 5.2%CVE-2018-10635—In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code EPSS 5.1%CVE-2017-13997—A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouchEPSS 5.1%CVE-2026-50507MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 5.0%CVE-2020-10920CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touchEPSS 4.9%CVE-2017-2637CRITICALA design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd isEPSS 4.8%CVE-2023-37483CRITICALImproper Access Control Vulnerabilities in SAP PowerDesignerEPSS 4.8%CVE-2022-36983HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not reqEPSS 4.7%CVE-2014-125118CRITICALeScan 5.5-2 Web Management Console Command InjectionEPSS 4.7%CVE-2026-58123CRITICALHermes WebUI < 0.51.788 Unauthenticated RCE via Terminal APIEPSS 4.6%CVE-2024-27890HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).EPSS 4.4%CVE-2025-34101CRITICALServiio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO ParameterEPSS 4.4%CVE-2026-0545HIGHMissing Authentication for Critical Function in mlflow/mlflowEPSS 4.4%CVE-2018-17924HIGHRockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could sEPSS 4.3%CVE-2022-25247CRITICALPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 4.1%CVE-2022-26501CRITICALVeeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).EPSS 4.1%KEV