Falhas do tipo CWE-306

2.619 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-7045MEDIUMCloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config ActionEPSS 0.4%CVE-2024-37767HIGHInsecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET reqEPSS 0.4%CVE-2017-20220HIGHServiio PRO 1.8 Unauthenticated Password Change via REST APIEPSS 0.4%CVE-2026-3558HIGHPhilips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-76701MEDIUMUnauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2026-44949HIGHUnauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhookEPSS 0.4%CVE-2025-61673HIGHKarapace is vulnerable to Authentication BypassEPSS 0.4%CVE-2022-41505MEDIUMAn access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UAREPSS 0.4%CVE-2026-83115HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versiEPSS 0.4%CVE-2024-22326MEDIUMIBM System Storage improper authenticationEPSS 0.4%CVE-2025-12348MEDIUMEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task ExecutionEPSS 0.4%CVE-2026-31846HIGHUnauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+EPSS 0.4%CVE-2023-45220HIGHThe Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol tEPSS 0.4%CVE-2025-20210HIGHCisco Catalyst Center Unprotected API EndpointEPSS 0.4%CVE-2024-58336HIGHAkuvox Smart Intercom S539 Unauthenticated Video Stream DisclosureEPSS 0.4%CVE-2024-53623HIGHIncorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.EPSS 0.4%CVE-2023-35874MEDIUMImproper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP PlatformEPSS 0.4%CVE-2026-60831HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions thaEPSS 0.4%CVE-2026-60742HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions thEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%