Weaknesses of type CWE-306

2,618 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-60361CRITICALVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%CVE-2026-61168HIGHVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.EPSS 0.4%CVE-2025-27803MEDIUMMissing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 0.4%CVE-2024-35143MEDIUMIBM Planning Analytics Local missing authenticationEPSS 0.4%CVE-2024-37303MEDIUMSynapse unauthenticated writes to the media repository allow planting of problematic contentEPSS 0.4%CVE-2026-42176MEDIUMScoold: Persistent Admin Takeover by Overwriting the admins Configuration Setting via Forged JWT (missing `jti` validation)EPSS 0.4%CVE-2026-32896MEDIUMOpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles PluginEPSS 0.4%CVE-2026-77644CRITICALCritical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise EditionEPSS 0.4%CVE-2025-34190HIGHVasion Print (formerly PrinterLogic) PrinterInstallerClientService Authentication Bypass via LD_PRELOAD HookingEPSS 0.4%CVE-2025-54851HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.4%CVE-2026-68070HIGHMissing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product LineupsEPSS 0.4%CVE-2026-5768HIGHFourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical FunctionEPSS 0.4%CVE-2025-49652CRITICALImproper access control allows arbitrary account creationEPSS 0.4%CVE-2025-27019CRITICALRemote shell service (RSH) in Infinera MTC-9EPSS 0.4%CVE-2026-30885MEDIUMWWBN AVideo - Unauthenticated IDOR - Playlist Information DisclosureEPSS 0.4%CVE-2026-60365CRITICALVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for EPSS 0.4%CVE-2026-87128CRITICALVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-73952CRITICALVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that areEPSS 0.4%CVE-2026-46892CRITICALVulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The suEPSS 0.4%CVE-2026-16771HIGHCVE-2026-16771EPSS 0.4%