Weaknesses of type CWE-306

2,613 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-43798HIGHChisel AUTH environment variable not respected in server entrypointEPSS 0.4%CVE-2026-100672HIGHgrav-plugin-comments before 1.2.11 Unauthenticated Information DisclosureEPSS 0.4%CVE-2024-48775HIGHAn issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update procEPSS 0.4%CVE-2024-48777HIGHLEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.EPSS 0.4%CVE-2024-48776HIGHAn issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update processEPSS 0.4%CVE-2026-34411MEDIUMAppsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIsEPSS 0.4%CVE-2026-63098MEDIUMTheHive 4.1.24 Unauthenticated Information Disclosure via /api/status EndpointEPSS 0.4%CVE-2026-82265MEDIUMZipkin Unauthenticated Spring Boot Actuator Endpoints ExposureEPSS 0.4%CVE-2024-48773HIGHAn issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update processEPSS 0.4%CVE-2025-11949HIGHDigiwin|EasyFlow .NET and EasyFlow AiNet - Missing AuthenticationEPSS 0.4%CVE-2026-24068HIGHMissing XPC Client & NSXPC endpoint validation leads to privilege escalation in Vienna Assistant (MacOS) - Vienna Symphonic LibraryEPSS 0.4%CVE-2026-55538HIGHPraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticatedEPSS 0.4%CVE-2026-41039HIGHInformation Disclosure Vulnerability in Quantum Networks Router QN-I-470EPSS 0.4%CVE-2023-45851HIGHThe Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  EPSS 0.4%CVE-2026-70979CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-23767CRITICALESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization,EPSS 0.4%CVE-2026-33543CRITICALFOSSBilling: Authentication bypass allows unauthenticated administrator creationEPSS 0.4%CVE-2026-70977CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-60591CRITICALVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2026-87223CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%