Weaknesses of type CWE-306

2,619 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2026-79645HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%CVE-2023-41333MEDIUMBypass of namespace restrictions in CiliumNetworkPolicy EPSS 0.4%CVE-2026-34280MEDIUMVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supporteEPSS 0.4%CVE-2024-41967HIGHWAGO: Boot Mode Manipulation in Multiple DevicesEPSS 0.4%CVE-2025-11171MEDIUMChartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative FunctionEPSS 0.4%CVE-2025-26468HIGHCyberData 011209 SIP Emergency Intercom Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-34266MEDIUMVulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supporEPSS 0.4%CVE-2026-57909CRITICALWatchGuard Agent path traversal allows unauthenticated remote code executionEPSS 0.4%CVE-2026-10577CRITICALRockwell Automation 1715 Redundant IO – Access Control VulnerabilityEPSS 0.4%CVE-2026-78255HIGHDJI Drone HTTP Media Server Allows Unauthenticated Access to Stored MediaEPSS 0.4%CVE-2024-7726MEDIUMArbitrary Code execution via exposed JTAG port in Kioxia CM6, PM6, PM7EPSS 0.4%CVE-2026-66875HIGHMira Hormone Monitor, Mira Android App Missing authentication for critical functionEPSS 0.4%CVE-2026-39393HIGHPost-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4msEPSS 0.4%CVE-2026-50507MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-4476MEDIUMYi Technology YI Home Camera CGI Endpoint ipc missing authenticationEPSS 0.4%CVE-2026-45567HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gptEPSS 0.4%CVE-2026-8185MEDIUMUGREEN CM933 Administrative missing authenticationEPSS 0.4%CVE-2024-55585CRITICALIn the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricEPSS 0.4%CVE-2024-5143MEDIUMA user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server EPSS 0.4%CVE-2026-45088HIGHDalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server ModeEPSS 0.4%