Falhas do tipo CWE-306

2.623 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-46935HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-60769HIGHVulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-47858HIGHlive information startup mode is vulnerable for remote code executionEPSS 0.3%CVE-2026-1410MEDIUMBeetel 777VR1 UART missing authenticationEPSS 0.3%CVE-2026-16876CRITICALAn authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbEPSS 0.3%CVE-2026-34288MEDIUMVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that iEPSS 0.3%CVE-2026-33070LOWFileRise has Unauthenticated Share Link DeletionEPSS 0.3%CVE-2026-34289MEDIUMVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that iEPSS 0.3%CVE-2026-89034HIGHTCH QRing R20_B006 Unauthenticated BLE AccessEPSS 0.3%CVE-2026-53649CRITICALJoro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEEPSS 0.3%CVE-2026-26048HIGHJinan USR IOT Technology Limited (PUSR) USR-W610 Missing Authentication for Critical FunctionEPSS 0.3%CVE-2024-48950HIGHAn issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attacEPSS 0.3%CVE-2021-20262—A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to takeEPSS 0.3%CVE-2025-71409HIGHNo Authentication for Very High Frequency Data Link messages used in CPDLCEPSS 0.3%CVE-2025-56562HIGHAn incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC aEPSS 0.3%CVE-2026-3527MEDIUMAJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022EPSS 0.3%CVE-2026-73245MEDIUMKestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authEPSS 0.3%CVE-2026-36603HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, incluEPSS 0.3%CVE-2026-52480MEDIUMAn issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd serviceEPSS 0.3%CVE-2025-25736MEDIUMKapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pEPSS 0.3%