Weaknesses of type CWE-306

2,619 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-61158HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-60689HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.4%CVE-2026-60704HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.4%CVE-2024-58300HIGHSiklu MultiHaul TG Series < 2.0.0 Unauthenticated Credential Disclosure VulnerabilityEPSS 0.4%CVE-2026-65114HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical funcEPSS 0.4%CVE-2023-39380—Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnorEPSS 0.4%CVE-2026-59506CRITICALPriority – CWE-306: Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-4370CRITICALImproper TLS Client/Server authentication and certificate verification on Database ClusterEPSS 0.4%CVE-2026-56725HIGHZammad: Denial of Service via OTRS Import ControllerEPSS 0.4%CVE-2026-6736MEDIUMAuthentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity providerEPSS 0.4%CVE-2026-2756LOWOmniPEMF NeoRhythm BLE missing authenticationEPSS 0.4%CVE-2023-31132HIGHCacti Privilege EscalationEPSS 0.4%CVE-2026-10281MEDIUMEnderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authenticationEPSS 0.4%CVE-2024-1662HIGHInformation Disclosure in Porty's PowerBankEPSS 0.4%CVE-2025-10267MEDIUMNewType Infortech|NUP Portal - Missing AuthenticationEPSS 0.4%CVE-2025-7774HIGHRockwell Automation ArmorBlock 5000 I/O – Web Server VulnerabilitiesEPSS 0.4%CVE-2024-36555CRITICALBuilt-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch EPSS 0.4%CVE-2024-8057MEDIUMImproper Access Control in danswer-ai/danswerEPSS 0.4%CVE-2024-8074CRITICALSensetive Data Exposure in Nomysoft Informatics' NomysemEPSS 0.4%CVE-2026-79645HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%