Weaknesses of type CWE-306

2,613 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-12108CRITICALMissing Authentication for Critical Function Survision License Plate Recognition CameraEPSS 0.4%CVE-2024-48771HIGHAn issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmwareEPSS 0.4%CVE-2024-45075HIGHIBM webMethods Integration privilege escalationEPSS 0.4%CVE-2026-45754MEDIUMSymfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event InjectionEPSS 0.4%CVE-2026-41273HIGHFlowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public ChatflowEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2026-60544HIGHVulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected areEPSS 0.4%CVE-2026-2844CRITICALTimePictra Authentication Bypass VulnerabilityEPSS 0.4%CVE-2025-0132MEDIUMCortex XDR Broker VM: Unauthenticated User Can Disable Internal ServicesEPSS 0.4%CVE-2026-61175CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2024-52285MEDIUMA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < VEPSS 0.4%CVE-2026-15416HIGHArgo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointEPSS 0.4%CVE-2026-59706CRITICALmem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_urlEPSS 0.4%CVE-2026-31983MEDIUMMissing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0EPSS 0.4%CVE-2024-21183HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-27509HIGHUnitree Go2 Missing DDS Authentication Enables Adjacent RCEEPSS 0.4%CVE-2024-48774HIGHAn issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware updatEPSS 0.4%CVE-2026-12183CRITICALNefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary CredentialsEPSS 0.4%CVE-2025-7115MEDIUMrowboatlabs rowboat Session route.ts PUT missing authenticationEPSS 0.4%CVE-2020-37146HIGHAptina AR0130 960P 1.3MP Camera - Remote Configuration DisclosureEPSS 0.4%