Falhas do tipo CWE-306

2.624 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-72542MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-22924HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthentiEPSS 0.3%CVE-2025-42926MEDIUMMissing Authentication check in SAP NetWeaver Application Server JavaEPSS 0.3%CVE-2026-60623HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.3%CVE-2026-72541MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-6673MEDIUMMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installEPSS 0.3%CVE-2024-51362MEDIUMThe LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed thEPSS 0.3%CVE-2026-26160HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62777HIGHWindows License Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50512HIGHMicrosoft PC Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50333HIGHWindows Spaceport.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-32326MEDIUMSHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the adminiEPSS 0.3%CVE-2026-61367HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69528HIGHWindows Shell Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61356HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26159HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61364HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61365HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-42976HIGHRemote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-11848HIGHIEI Integration Corp| iRM-IEI Remote Management - Missing AuthenticationEPSS 0.3%