Falhas do tipo CWE-306

2.622 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2023-29061MEDIUMLack of Adequate BIOS AuthenticationEPSS 0.4%CVE-2023-7325CRITICALMingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRFEPSS 0.4%CVE-2026-82276MEDIUMStarRocks Frontend REST Handlers Bypass the Base Class Authentication GateEPSS 0.4%CVE-2026-54068MEDIUMSiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIconEPSS 0.4%CVE-2026-86506MEDIUMIn JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling dataEPSS 0.4%CVE-2025-3474MEDIUMPanels - Critical - Access bypass - SA-CONTRIB-2025-033EPSS 0.4%CVE-2024-47912HIGHA vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an uEPSS 0.4%CVE-2026-0283MEDIUMPAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)EPSS 0.4%CVE-2026-76447MEDIUMCisco Identity Services Engine Certificate Reload VulnerabilityEPSS 0.4%CVE-2026-56677HIGH9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test EndpointEPSS 0.4%CVE-2025-14349HIGHBusiness Logic Error in Universal Software's FlexCity/KioskEPSS 0.4%CVE-2026-48692HIGHFastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initializEPSS 0.4%CVE-2026-50082MEDIUMAqara Developer Portal insecure authentication tokenEPSS 0.4%CVE-2026-34949MEDIUMCombodo iTop: Unauthenticated user can delete .readonly fileEPSS 0.4%CVE-2026-40856HIGHConfig disclosure in T-Mobile 5G Box IDU routersEPSS 0.4%CVE-2023-31227HIGHThe hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confiEPSS 0.4%CVE-2026-49471HIGHSerena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEEPSS 0.4%CVE-2026-60557MEDIUMVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2025-41689HIGHWiesemann & Theis: Motherbox 3 allows unauthenticated read-only DB accessEPSS 0.4%CVE-2025-3319HIGHIBM Spectrum Protect Server authentication bypassEPSS 0.4%