Weaknesses of type CWE-306

2,612 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-5872MEDIUMeGauge EG3000 Energy Monitor Setting missing authenticationEPSS 0.5%CVE-2026-32594MEDIUMParse Server GraphQL WebSocket endpoint bypasses security middlewareEPSS 0.5%CVE-2026-32957MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenEPSS 0.5%CVE-2026-84831HIGHMandatory MFA bypass before enrollmentEPSS 0.5%CVE-2025-5876MEDIUMLucky LM-520-SC/LM-520-FSC/LM-520-FSC-SAM missing authenticationEPSS 0.5%CVE-2025-41655HIGHPEPPERL+FUCHS: Attacker can cause a DoS via URLEPSS 0.5%CVE-2026-32962MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuEPSS 0.5%CVE-2026-84078CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-83197CRITICALVulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions thatEPSS 0.5%CVE-2019-25248HIGHBeward N100 M2.1.6 Unauthenticated RTSP Video Stream DisclosureEPSS 0.5%CVE-2022-50977HIGHMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via HTTPEPSS 0.5%CVE-2018-25141HIGHFLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2026-34227MEDIUMSliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP InterfaceEPSS 0.5%CVE-2026-79687CRITICALDell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access EPSS 0.5%CVE-2026-80132HIGHell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticatEPSS 0.5%CVE-2025-53037CRITICALVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.5%CVE-2026-92972HIGHSGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpointEPSS 0.5%CVE-2026-47769MEDIUMAPIFold Vulnerable to Unauthenticated Webhook Event InjectionEPSS 0.5%CVE-2024-21846MEDIUMElectrolink FM/DAB/TV Transmitter Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-2234CRITICALHGiga|C&Cm@il - Missing AuthenticationEPSS 0.5%