Falhas do tipo CWE-306

2.619 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-35514MEDIUMUnauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions in ChartbrewEPSS 0.4%CVE-2024-6406HIGHSensetive Data Exposure in Yordam Information Technology's Mobile Library ApplicationEPSS 0.4%CVE-2025-59345HIGHDragonfly did not enable authentication for some Manager’s endpointsEPSS 0.4%CVE-2025-41716MEDIUMUnauthenticated User Enumeration via Missing AuthenticationEPSS 0.4%CVE-2025-43983CRITICALKuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_proceEPSS 0.4%CVE-2024-41791MEDIUMA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not autheEPSS 0.4%CVE-2026-97231MEDIUMvolotat Anagnorisis Socket.IO Connect app.py missing authenticationEPSS 0.4%CVE-2026-25751CRITICALFUXA Unauthenticated Exposure of Plaintext Database CredentialsEPSS 0.4%CVE-2026-54036MEDIUMLibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP VerificationEPSS 0.4%CVE-2024-40091MEDIUMVilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve lEPSS 0.4%CVE-2025-54864MEDIUMHydra missing authentication when triggering evaluations through GitHub and Gitea pluginsEPSS 0.4%CVE-2026-44320HIGHfree5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing pathEPSS 0.4%CVE-2023-44116—Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may caEPSS 0.4%CVE-2024-0336CRITICALImproper Access Control in EMTA Grups PDKSEPSS 0.4%CVE-2026-89027MEDIUMminiOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication DowngradeEPSS 0.4%CVE-2026-0842MEDIUMFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authenticationEPSS 0.4%CVE-2026-13125HIGHGeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerabilityEPSS 0.4%CVE-2026-17057MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]EPSS 0.4%CVE-2023-28761MEDIUMMissing Authentication check in SAP NetWeaver Enterprise PortalEPSS 0.4%CVE-2026-60255HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%