Falhas do tipo CWE-306

2.623 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-52551CRITICALProprietary protocol allows for unauthenticated file operationsEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%CVE-2025-52182HIGHThe Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.EPSS 0.3%CVE-2023-7328MEDIUMScreen SFT DAB 600/C <= 1.9.3 Unauthenticated Information DisclosureEPSS 0.3%CVE-2026-18111HIGHConcrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verificationEPSS 0.3%CVE-2026-76640HIGHUnitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning StackEPSS 0.3%CVE-2024-21824MEDIUMImproper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER IEPSS 0.3%CVE-2026-32291HIGHGL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial consoleEPSS 0.3%CVE-2025-20085HIGHA denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted EPSS 0.3%CVE-2026-60671HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). SupportEPSS 0.3%CVE-2026-44830HIGHEmpty API_TOKEN disables authentication on network-reachable HTTP/SSE transportEPSS 0.3%CVE-2026-60235HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.3%CVE-2024-49572HIGHA denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pEPSS 0.3%CVE-2025-42875MEDIUMMissing Authentication check in SAP NetWeaver Internet Communication FrameworkEPSS 0.3%CVE-2026-75754CRITICALMissing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center aEPSS 0.3%CVE-2025-51543CRITICALAn issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_pEPSS 0.3%CVE-2025-65007HIGHMissing Authentication for Critical Function in WODESYS WD-R608U routerEPSS 0.3%CVE-2026-82784MEDIUMMissing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may exEPSS 0.3%CVE-2026-87195HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-4382MEDIUMGrub2: grub allow access to encrypted device through cli once root device is unlocked via tpmEPSS 0.3%