Weaknesses of type CWE-306

2,613 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-65012MEDIUMInvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderEPSS 0.4%CVE-2024-7015HIGHImproper Authentication in Profelis Informatics and Consulting's PassBOXEPSS 0.4%CVE-2026-82282HIGHAtlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated CallersEPSS 0.4%CVE-2026-80208HIGHAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Account Closure EndpointsEPSS 0.4%CVE-2026-12722HIGHAuthentication Bypass in FTC Software's E-Commerce Management PanelEPSS 0.4%CVE-2026-22207CRITICALOpenViking Missing root_api_key Allows Anonymous ROOT AccessEPSS 0.4%CVE-2024-33622MEDIUMMissing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerabilitEPSS 0.4%CVE-2023-39436MEDIUMInformation Disclosure in SAP Supplier Relationship ManagementEPSS 0.4%CVE-2026-27471CRITICALERP: Document access through endpoints due to missing validationEPSS 0.4%CVE-2026-5029HIGHRCE in Code Runner MCP ServerEPSS 0.4%CVE-2023-27983MEDIUMA CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of rEPSS 0.4%CVE-2026-28458HIGHOpenClaw 2026.1.20 < 2026.2.1 - Missing Authentication in Browser Relay /cdp WebSocket EndpointEPSS 0.4%CVE-2026-50225HIGHAccount Creation ExhaustionEPSS 0.4%CVE-2026-57476MEDIUMDeloitte AI Assist for Customer unauthenticated RAG corpus read and writeEPSS 0.4%CVE-2026-34732MEDIUMAVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 EndpointsEPSS 0.4%CVE-2025-65731MEDIUMAn issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical acceEPSS 0.4%CVE-2026-0647HIGHRockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple VulnerabilitiesEPSS 0.4%CVE-2026-68929CRITICALFastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorizationEPSS 0.4%CVE-2026-61176MEDIUMVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2026-44775MEDIUMKavita: No authentication at /api/Reader/imageEPSS 0.4%