Falhas do tipo CWE-306

2.622 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-83334HIGHVulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versionsEPSS 0.4%CVE-2025-63435MEDIUMXtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible foEPSS 0.4%CVE-2025-8754HIGHABB AbilityTM zenon Remote Transport VulnerabilityEPSS 0.4%CVE-2026-68578HIGHArcadeDB before 26.7.3 Authentication Bypass via MCP TransportEPSS 0.4%CVE-2026-59715LOWOpen WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)EPSS 0.4%CVE-2026-57495HIGHAgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)EPSS 0.4%CVE-2026-47019HIGHVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected EPSS 0.4%CVE-2026-60653HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2024-43272MEDIUMWordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Unpublished Campaign Viewer vulnerabilityEPSS 0.4%CVE-2026-19441MEDIUMUnauthenticated API Allows Analytics Data Manipulation in IKAS Technology's RushEPSS 0.4%CVE-2026-70805HIGHVulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versiEPSS 0.4%CVE-2024-7079MEDIUMOpenshift-console: unauthenticated installation of helm chartsEPSS 0.4%CVE-2023-30612MEDIUMMalicious HTTP requests could close arbitrary opening file descriptors in cloud-hypervisorEPSS 0.4%CVE-2024-9430MEDIUMGet Quote For Woocommerce – Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV DownloadEPSS 0.4%CVE-2026-5267HIGHUnauthenticated Event Stream Exposure of Session Tokens in Navigator NCSEPSS 0.4%CVE-2026-19908HIGHPAX Technology Q80 XCB Daemon Missing Authentication VulnerabilityEPSS 0.4%CVE-2018-25241HIGHVPN Browser+ 1.1.0.0 Denial of ServiceEPSS 0.4%CVE-2026-81032CRITICALNebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime ConfigurationEPSS 0.4%CVE-2026-49217HIGHMailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictionsEPSS 0.4%CVE-2026-83305HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%