Falhas do tipo CWE-306

2.623 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-87195HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-4382MEDIUMGrub2: grub allow access to encrypted device through cli once root device is unlocked via tpmEPSS 0.3%CVE-2026-61135HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.3%CVE-2025-41090HIGHImproper Access Control in CCN-CERT microCLAUDIAEPSS 0.3%CVE-2024-41968MEDIUMWAGO: Docker Settings Manipulation in Multiple DevicesEPSS 0.3%CVE-2025-4560MEDIUMNetvision ISOinsight - Missing AuthenticationEPSS 0.3%CVE-2025-15346CRITICALwolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirementEPSS 0.3%CVE-2026-54246MEDIUMSkipper routesrv-no-auth: All routesrv API Endpoints Lack AuthenticationEPSS 0.3%CVE-2025-30126MEDIUMAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remoEPSS 0.3%CVE-2025-25068HIGHBypassing MFA Enforcement on Plugin EndpointsEPSS 0.3%CVE-2025-36757MEDIUMBypass of administrator login screen in SolaX CloudEPSS 0.3%CVE-2022-31022MEDIUMMissing Role Based Access Control for the REST handlers in bleve/http packageEPSS 0.3%CVE-2020-27225—In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web seEPSS 0.3%CVE-2025-11728MEDIUMOceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status UpdateEPSS 0.3%CVE-2026-83343HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.3%CVE-2026-19853MEDIUMCyberTutor|NewSiteServer (NSS) - Missing AuthenticationEPSS 0.3%CVE-2023-37325MEDIUMD-Link DAP-2622 DDP Set SSID List Missing Authentication VulnerabilityEPSS 0.3%CVE-2026-44413HIGHIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised accessEPSS 0.3%CVE-2026-46934HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-60497HIGHVulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported versiEPSS 0.3%