Weaknesses of type CWE-306

2,618 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2023-41255HIGHThe vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abuEPSS 0.4%CVE-2026-83461HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2026-45577MEDIUMNeotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypassEPSS 0.4%CVE-2026-83266HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that EPSS 0.4%CVE-2026-25885CRITICALPolarLearn allows Unauthenticated WebSocket access allows subscribing to and posting in arbitrary group chatsEPSS 0.4%CVE-2024-26263MEDIUMEBM Technologies RISWEB - Improper Access ControlEPSS 0.4%CVE-2026-5749HIGHInadequate access control vulnerability in FullstepEPSS 0.4%CVE-2026-77248HIGHMCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transportEPSS 0.4%CVE-2025-32738MEDIUMMissing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlieEPSS 0.4%CVE-2025-55221HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70EPSS 0.4%CVE-2026-58071HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal AdministEPSS 0.4%CVE-2025-55222HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70EPSS 0.4%CVE-2025-54848HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.4%CVE-2026-42331HIGHFOSSBilling missing authorization in guest Invoice API endpointsEPSS 0.4%CVE-2024-32764CRITICALmyQNAPcloud LinkEPSS 0.4%CVE-2026-29132MEDIUMESWmail-Verify BypassEPSS 0.4%CVE-2026-60580HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2026-74245MEDIUMQuay: unauthenticated exported logs download in quayEPSS 0.4%CVE-2026-59971CRITICALMySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)EPSS 0.4%CVE-2025-30111HIGHOn IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized usEPSS 0.4%