Weaknesses of type CWE-306

2,619 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-55585CRITICALIn the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricEPSS 0.4%CVE-2026-40184LOWUnauthenticated Access to Uploaded Files in TREKEPSS 0.4%CVE-2025-40736CRITICALA vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorEPSS 0.4%CVE-2025-48742MEDIUMThe installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.EPSS 0.4%CVE-2026-45089HIGHDalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server ModeEPSS 0.4%CVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-18771HIGHMissing Authentication for Critical Function in TMT Machine's Talassoft Industrial Management SoftwareEPSS 0.4%CVE-2026-89176HIGHHowyar|WeenyGenius - Missing AuthenticationEPSS 0.4%CVE-2026-87200HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2025-32876MEDIUMAn issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure EPSS 0.4%CVE-2026-10617MEDIUMnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authenticationEPSS 0.4%CVE-2025-61752HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-35450MEDIUMWWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.phpEPSS 0.4%CVE-2026-86064HIGHKlever-Go: /log controls global node loggingEPSS 0.4%CVE-2025-27214CRITICALA Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical oEPSS 0.4%CVE-2026-79961MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%CVE-2024-31525HIGHPeppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges toEPSS 0.4%CVE-2022-0922MEDIUMICSMA-22-088-01 Philips e-AlertEPSS 0.4%CVE-2025-14577CRITICALPHP Function Injection in Slican NPC/IPL/IPM/IPUEPSS 0.4%CVE-2024-37767HIGHInsecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET reqEPSS 0.4%