Weaknesses of type CWE-306

2,613 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-65311MEDIUMMissing authentication for logging-configuration endpointEPSS 0.5%CVE-2023-54342CRITICALEclipse Equinox OSGi 3.8-3.18 Console Remote Code ExecutionEPSS 0.5%CVE-2026-61203CRITICALVulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is EPSS 0.5%CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%CVE-2024-40405HIGHIncorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker viaEPSS 0.5%CVE-2023-34392HIGHMissing Authentication for Critical FunctionEPSS 0.5%CVE-2019-25236HIGHiSeeQ Hybrid DVR WH-H4 1.03R Unauthenticated Live Stream DisclosureEPSS 0.5%CVE-2026-15576MEDIUMAgent receiver accepts mTLS requests without a client certificateEPSS 0.5%CVE-2026-55534HIGHPraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executionEPSS 0.5%CVE-2026-89263MEDIUMMoguBlog through 6.2 Missing Authentication on the Comment Email-Notification EndpointEPSS 0.5%CVE-2025-3090HIGHMB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24EPSS 0.5%CVE-2023-24527MEDIUMImproper Access Control in SAP NetWeaver AS Java for Deploy ServiceEPSS 0.5%CVE-2023-0116HIGHThe reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect avaiEPSS 0.5%CVE-2026-53868HIGHCapgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and DeletionEPSS 0.5%CVE-2025-61777CRITICALFlagForge Allows Unauthenticated Badge Template API AccessEPSS 0.5%CVE-2026-70559HIGHDinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAllEPSS 0.5%CVE-2021-36780HIGHUnauthorized data access from replicas through vulnerable instance manager podsEPSS 0.5%CVE-2023-5253MEDIUMCheck Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0EPSS 0.5%CVE-2026-42864CRITICALFireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theftEPSS 0.4%CVE-2026-20343HIGHCisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service VulnerabilityEPSS 0.4%