Weaknesses of type CWE-306

2,612 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-37495MEDIUMHCL Domino is susceptible to a weak cryptography vulnerabilityEPSS 0.5%CVE-2026-2234CRITICALHGiga|C&Cm@il - Missing AuthenticationEPSS 0.5%CVE-2026-60439HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2025-34434CRITICALAVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and DeletionEPSS 0.5%CVE-2026-61246HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-77097HIGHPrivate Metrics Server Denial of ServiceEPSS 0.5%CVE-2019-25686HIGHCore FTP 2.0 build 653 PBSZ Unauthenticated Denial of ServiceEPSS 0.5%CVE-2026-75479HIGHJimuReport Unauthenticated Report Listing and Share Token DisclosureEPSS 0.5%CVE-2024-8419HIGHImproper Access Control vulnerability in AC4xxS devicesEPSS 0.5%CVE-2025-32377MEDIUMRasa Pro Missing Authentication For Voice Connector APIsEPSS 0.5%CVE-2026-74243MEDIUMQuay: unauthenticated secscan notification endpoint in quay when psk is unsetEPSS 0.5%CVE-2026-86681HIGHBroken Access Control vulnerabilityEPSS 0.5%CVE-2026-83327CRITICALVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2026-70861HIGHVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supportEPSS 0.5%CVE-2023-33247HIGHTalend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be EPSS 0.5%CVE-2025-69285HIGHSQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerabilityEPSS 0.5%CVE-2026-1332MEDIUMHAMASTAR Technology|MeetingHub - Missing AuthenticationEPSS 0.5%CVE-2024-11980HIGHBillion Electric router - Missing AuthenticationEPSS 0.5%CVE-2022-43555HIGHIvanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2022-43554HIGHIvanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%