Falhas do tipo CWE-306

2.624 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-48953HIGHAn issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proEPSS 0.3%CVE-2021-34983MEDIUMNETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-43881MEDIUMWWBN AVideo: Unauthenticated User Enumeration in `objects/users.json.php` via `isCompany` Parameter Flips `$ignoreAdmin = true` and Defeats Admin-Only Listing GuardEPSS 0.3%CVE-2026-0492HIGHPrivilege escalation vulnerability in SAP HANA databaseEPSS 0.3%CVE-2018-25140CRITICALFLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated Websocket Device ManipulationEPSS 0.3%CVE-2026-12199HIGHUnauthenticated Denial of Service in nltk.app.wordnet_appEPSS 0.3%CVE-2025-12477CRITICALServer Version DisclosureEPSS 0.3%CVE-2026-76439MEDIUMCisco Identity Services Engine Event Injection VulnerabilityEPSS 0.3%CVE-2022-48496—Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause maEPSS 0.3%CVE-2026-54367HIGHCentreStack < 17.2 Unauthenticated API Authorization BypassEPSS 0.3%CVE-2026-66098HIGHMira Hormone Monitor, Mira Android App Missing authentication for critical functionEPSS 0.3%CVE-2022-48494—Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause maEPSS 0.3%CVE-2025-61756HIGHVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.3%CVE-2025-56405HIGHAn issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP serviceEPSS 0.3%CVE-2025-62619MEDIUMMissing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrievEPSS 0.3%CVE-2025-54850HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.3%CVE-2025-54849HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.3%CVE-2026-88410HIGHThe graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the EPSS 0.3%CVE-2025-12049CRITICALMissing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may EPSS 0.3%CVE-2026-100192MEDIUMX-SpringBoot through 6.0 Credential Exposure via Unauthenticated EndpointEPSS 0.3%