Falhas do tipo CWE-306

2.619 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-61201CRITICALVulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported versEPSS 0.4%CVE-2026-70924HIGHVulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versionsEPSS 0.4%CVE-2026-60277HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%CVE-2026-60417HIGHVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%CVE-2026-61163HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-61137HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.4%CVE-2026-61307HIGHVulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application ObjectsEPSS 0.4%CVE-2026-60979HIGHVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2026-60543HIGHVulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected areEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%CVE-2026-60169HIGHVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2024-42456HIGHA vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates crEPSS 0.4%CVE-2024-21146HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affecEPSS 0.4%CVE-2025-30762HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-2491MEDIUMSocomec DIRIS A-40 HTTP API Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-20326CRITICALCisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical FunctionEPSS 0.4%CVE-2024-49399HIGHMissing Authentication for Critical Function in Elvaco M-Bus Metering Gateway CMe3100EPSS 0.4%CVE-2023-45140MEDIUMGroup-based JIT MFA bypass on scp and sftp in The BastionEPSS 0.4%CVE-2026-15563HIGHWildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dosEPSS 0.4%CVE-2025-59345HIGHDragonfly did not enable authentication for some Manager’s endpointsEPSS 0.4%