Falhas do tipo CWE-306

2.624 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-0942MEDIUMRede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.5 - Missing Authorization to Unauthenticated Rede Order Logs DeletionEPSS 0.3%CVE-2026-100192MEDIUMX-SpringBoot through 6.0 Credential Exposure via Unauthenticated EndpointEPSS 0.3%CVE-2026-73222HIGHClaude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)EPSS 0.3%CVE-2025-12476CRITICALResource Lacking AuthNEPSS 0.3%CVE-2024-34268HIGHEQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth EPSS 0.3%CVE-2018-19636HIGHLocal root exploit via inclusion of attacker controlled shell scriptEPSS 0.3%CVE-2023-46096MEDIUMA vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authentEPSS 0.3%CVE-2025-8627HIGHUnauthenticated Protocol Commands on TP-Link KP303EPSS 0.3%CVE-2025-11771MEDIUMCryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.7 - Missing Authentication to Unauthenticated Presale UpdateEPSS 0.3%CVE-2025-6226MEDIUMIDOR in CreatePost API allows for timeboxed message disclosureEPSS 0.3%CVE-2025-60856MEDIUMReolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical accEPSS 0.3%CVE-2020-25697—A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker tEPSS 0.3%CVE-2026-71203MEDIUMchangedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI SchemaEPSS 0.3%CVE-2025-23194MEDIUMMissing Authentication check in SAP NetWeaver Enterprise Portal (OBN component)EPSS 0.3%CVE-2026-12989HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.3%CVE-2026-8335HIGHMissing authentication in Aix-DBEPSS 0.3%CVE-2025-32782MEDIUMAsh Authentication email link auto-click account confirmation vulnerabilityEPSS 0.3%CVE-2026-5777HIGHSecurity Misconfiguration Vulnerability in Atom 3x ProjectorEPSS 0.3%CVE-2024-9919HIGHMissing Authentication Check in parisneo/lollms-webuiEPSS 0.3%CVE-2026-59804HIGHMidscene Bridge Server - Session Hijack via Unauthenticated WebSocketEPSS 0.3%