Weaknesses of type CWE-306

2,613 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-1332MEDIUMHAMASTAR Technology|MeetingHub - Missing AuthenticationEPSS 0.5%CVE-2024-11980HIGHBillion Electric router - Missing AuthenticationEPSS 0.5%CVE-2025-52024CRITICALA vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthentEPSS 0.5%CVE-2025-7679CRITICALSession ID Basic Auth BypassEPSS 0.5%CVE-2024-48920CRITICALPutongOJ: unprivileged users can escalate privileges by constructing requestsEPSS 0.5%CVE-2026-30866HIGHCombodo iTop: Insecured access to uploaded images via sniffed urlEPSS 0.5%CVE-2026-1724MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.5%CVE-2026-12562HIGHToptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-54598HIGHMissing Authentication for Critical Function in wallosEPSS 0.5%CVE-2024-40404CRITICALCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web SockeEPSS 0.5%CVE-2026-24790HIGHWelker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller Missing Authentication for Critical FunctionEPSS 0.5%CVE-2022-50594HIGHAdvantech iView < v5.7.04 Build 6425 data Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2026-73710HIGHUnauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric ComposerEPSS 0.5%CVE-2024-10774HIGHSICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIsEPSS 0.5%CVE-2025-25265MEDIUMUnauthenticated File Read via Web InterfaceEPSS 0.5%CVE-2026-73706HIGHAuthentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized ChangesEPSS 0.5%CVE-2026-18673MEDIUMKong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authenticationEPSS 0.5%CVE-2019-25240HIGHRifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticated Live Stream Disclosure via animate.cgiEPSS 0.5%CVE-2025-7405HIGHInformation Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU moduleEPSS 0.5%CVE-2026-56321MEDIUMCapgo - Missing Authentication Middleware on GET /private/role_bindings EndpointEPSS 0.5%