Falhas do tipo CWE-306

2.624 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-13030MEDIUMAll versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An EPSS 0.3%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2025-61778CRITICALAkka.Remote TLS did not properly implement certificate-based authenticationEPSS 0.3%CVE-2026-50451HIGHWindows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-42885MEDIUMMissing authentication in SAP HANA 2.0 (hdbrss)EPSS 0.3%CVE-2026-61267HIGHVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versEPSS 0.3%CVE-2023-31033MEDIUMCVEEPSS 0.3%CVE-2025-7031MEDIUMConfig Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086EPSS 0.3%CVE-2025-12349MEDIUMEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue TriggerEPSS 0.3%CVE-2026-69674MEDIUMWindows Modern Device Management (MDM) Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2024-27892HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).EPSS 0.3%CVE-2026-83991MEDIUMWindows Cloud Files Mini Filter Driver Tampering VulnerabilityEPSS 0.3%CVE-2026-69554MEDIUMMicrosoft Windows Search Component Tampering VulnerabilityEPSS 0.3%CVE-2026-73004MEDIUMWindows Autopilot Tampering VulnerabilityEPSS 0.3%CVE-2026-72964MEDIUMWindows Internet Connection Sharing (ICS) Tampering VulnerabilityEPSS 0.3%CVE-2026-69321MEDIUMWindows Power Dependency Coordinator Tampering VulnerabilityEPSS 0.3%CVE-2026-46997MEDIUMVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported vEPSS 0.3%CVE-2025-0257MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other servicesEPSS 0.3%CVE-2026-72542MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-60781HIGHVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.3%