Falhas do tipo CWE-306

2.622 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2018-25241HIGHVPN Browser+ 1.1.0.0 Denial of ServiceEPSS 0.4%CVE-2026-81032CRITICALNebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime ConfigurationEPSS 0.4%CVE-2026-83305HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%CVE-2026-49217HIGHMailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictionsEPSS 0.4%CVE-2024-3774MEDIUMaEnrich Technology a+HRD - Exposure of Sensitive DataEPSS 0.4%CVE-2025-11986MEDIUMCrypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication StateEPSS 0.4%CVE-2025-6792MEDIUMOne to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message InterceptionEPSS 0.4%CVE-2025-53789HIGHWindows StateRepository API Server file Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2018-25246HIGHWikipedia 12.0 Denial of Service via SearchEPSS 0.4%CVE-2026-86106HIGHSecurity Advisory 0179EPSS 0.4%CVE-2026-61590HIGHdjust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUGEPSS 0.4%CVE-2026-28352MEDIUMIndico missing access check in event series management APIEPSS 0.4%CVE-2024-13173MEDIUMHealth information leakage vulnerabilityEPSS 0.4%CVE-2024-13186MEDIUMMinigameCenter information leakage vulnerabilityEPSS 0.4%CVE-2026-47671MEDIUMNhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secretsEPSS 0.4%CVE-2024-13185MEDIUMMinigameCenter module information leakage vulnerabilityEPSS 0.4%CVE-2026-35274HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.4%CVE-2026-60810HIGHVulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). SupportedEPSS 0.4%CVE-2026-60652HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2026-87197HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%