Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-73296CRITICALMicrosoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosureEPSS 2.9%CVE-2026-59801CRITICAL9Router 0.4.41 - Unauthenticated API Exposure via /api/providersEPSS 2.9%CVE-2020-12500CRITICALPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productsEPSS 2.9%CVE-2025-34112CRITICALRiverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCEEPSS 2.9%CVE-2026-9103CRITICALUnauthenticated Superuser Token Issuance via Auto-Login EndpointEPSS 2.8%CVE-2020-10921CRITICALThis vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen EPSS 2.8%CVE-2026-42796CRITICALArelle < 2.39.10 Unauthenticated RCE via /rest/configureEPSS 2.7%CVE-2019-10919A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp couEPSS 2.7%CVE-2019-18339CRITICALA vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVEPSS 2.7%CVE-2018-18995Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativEPSS 2.6%CVE-2019-10922A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WEPSS 2.6%CVE-2018-0377A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, EPSS 2.6%CVE-2018-0376A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to accesEPSS 2.6%CVE-2018-0374A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connecEPSS 2.6%CVE-2021-43832CRITICALImproper Access Control in spinnakerEPSS 2.6%CVE-2018-4854A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to porEPSS 2.5%CVE-2025-0896CRITICALOrthanc Server Missing Authentication for Critical FunctionEPSS 2.5%CVE-2020-10272CRITICALRVD#2554: MiR ROS computational graph presents no authentication mechanismsEPSS 2.5%CVE-2026-41452CRITICALKrayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setupEPSS 2.5%CVE-2025-34121CRITICALIdera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCEEPSS 2.4%