Falhas do tipo CWE-306

2.623 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-46912CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions thatEPSS 0.4%CVE-2026-87196HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-35274HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.4%CVE-2022-26394MEDIUMUnauthenticated network reconfiguration via TCP/UDPEPSS 0.4%CVE-2026-60586HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.4%CVE-2026-33715HIGHChamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer actionEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2025-7635HIGHCalix GigaCenter ONT - Unauthenticated TelnetEPSS 0.4%CVE-2026-6272HIGHA client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStreamEPSS 0.4%CVE-2025-13483HIGHMissing Authentication for Critical Function in SiRcom SMART Alert (SiSA)EPSS 0.4%CVE-2026-35584MEDIUMFreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and EnumerationEPSS 0.4%CVE-2021-47709HIGHCOMMAX Smart Home Ruvie CCTV Bridge DVR Service Config Write / DoSEPSS 0.4%CVE-2021-47710HIGHCOMMAX Smart Home Ruvie CCTV Bridge DVR Service RTSP Credentials DisclosureEPSS 0.4%CVE-2026-17635CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2020-5326MEDIUMAffected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage ReEPSS 0.3%CVE-2026-53714HIGHEnvoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceModeEPSS 0.3%CVE-2026-50227MEDIUMMQTT WebSocket Command Execution Vulnerability in NitroSenseEPSS 0.3%CVE-2026-80207MEDIUMAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Notification Create EndpointEPSS 0.3%CVE-2019-25738CRITICALWordPress Hybrid Composer 1.4.6 Unauthenticated Settings ChangeEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%