Falhas do tipo CWE-306

2.622 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-41689HIGHWiesemann & Theis: Motherbox 3 allows unauthenticated read-only DB accessEPSS 0.4%CVE-2026-54365HIGHCentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dllEPSS 0.4%CVE-2026-71566CRITICALKubeVirt backend is not authenticatedEPSS 0.4%CVE-2025-59780HIGHGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-61239CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supporEPSS 0.4%CVE-2026-8694MEDIUMImproper access control on the API documentation endpoint in PowerShell UniversalEPSS 0.4%CVE-2026-2675MEDIUMMissing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.EPSS 0.4%CVE-2025-14300HIGHUnauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425EPSS 0.4%CVE-2025-14294MEDIUMRazorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order ModificationEPSS 0.4%CVE-2025-47850MEDIUMIn JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloningEPSS 0.4%CVE-2026-77977HIGHEbyte NA111-M Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-10711HIGHRCE in Akınsoft's CafePlusEPSS 0.4%CVE-2024-40087CRITICALVilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 alEPSS 0.4%CVE-2025-7970HIGHRockwell Automation FactoryTalk Activation Manager Lack of Encryption VulnerabilityEPSS 0.4%CVE-2026-49195HIGHPredator Connect W6x: unauthenticated Debug ServiceEPSS 0.4%CVE-2025-48733HIGHDuraComm DP-10iN-100-MU Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-7187HIGHImproper Authentication in Universal Sotware's UKBSEPSS 0.4%CVE-2026-81664MEDIUMOpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /system/telemetry RouteEPSS 0.4%CVE-2025-11672MEDIUMEBM Technologies|Uniweb/SoliPACS WebServer - Missing AuthenticationEPSS 0.4%CVE-2025-11671MEDIUMEBM Technologies|Uniweb/SoliPACS WebServer - Missing AuthenticationEPSS 0.4%