Weaknesses of type CWE-306

2,619 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-6582MEDIUMBroken Access Control in lunary-ai/lunaryEPSS 0.4%CVE-2022-48299HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2026-15581HIGHTrustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wideEPSS 0.4%CVE-2025-30111HIGHOn IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized usEPSS 0.4%CVE-2022-48300HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2022-48289HIGHThe bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2026-60967HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported versions that are affecEPSS 0.4%CVE-2026-19971MEDIUMLB-Link WR1210M Backup Endpoint backup.cgi main missing authenticationEPSS 0.4%CVE-2025-66049HIGHUnprotected RTSP stream in Vivotek IP7137 camerasEPSS 0.4%CVE-2026-86259CRITICALOpenMAIC before 1.0.1 SSRF via Environment-Gated URL ValidationEPSS 0.4%CVE-2026-46789CRITICALVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that EPSS 0.4%CVE-2025-41654HIGHPEPPERL+FUCHS: Profinet Gateway LB8122A.1.EL – Device is affected by information disclosure via the SNMP protocolEPSS 0.4%CVE-2025-8279HIGHMissing Authentication for Critical Function in GitLab Language ServerEPSS 0.4%CVE-2026-60605HIGHVulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESAEPSS 0.4%CVE-2020-36963HIGHIntelbras Router RF 301K 1.1.2 - Authentication BypassEPSS 0.4%CVE-2026-60359HIGHVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%CVE-2026-61158HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-60263HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.4%CVE-2026-61186CRITICALVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.4%CVE-2026-87205HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%