Falhas do tipo CWE-306

2.627 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-47038LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0EPSS 0.3%CVE-2026-76444MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-36457MEDIUMSymantec Privileged Access Manager Authentication Bypass vulnerabilityEPSS 0.3%CVE-2023-2827HIGHMissing Authentication in SAP Plant Connectivity and Production Connector for SAP DigitalEPSS 0.3%CVE-2025-13779HIGHConfiguration Data SpillEPSS 0.3%CVE-2025-6920MEDIUMAi-inference-server: authentication bypass via unprotected inference endpoint in apiEPSS 0.3%CVE-2024-35585HIGHOxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.EPSS 0.3%CVE-2025-53847MEDIUMA missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7EPSS 0.3%CVE-2026-26027HIGHGLPI has an Unauthenticated Stored XSS via inventoryEPSS 0.3%CVE-2026-46409CRITICALOpenYak local API: unauthenticated CSRF chain leads to Remote Code ExecutionEPSS 0.3%CVE-2024-40408HIGHCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. ThisEPSS 0.3%CVE-2026-60616MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.3%CVE-2025-65828MEDIUMAn unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these deviEPSS 0.3%CVE-2026-5300MEDIUMMissing Authentication for Critical Function in coolercontroldEPSS 0.3%CVE-2025-8450HIGHUnrestricted File Upload in FileCatalystEPSS 0.3%CVE-2026-15063MEDIUMTrustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabledEPSS 0.3%CVE-2024-48952MEDIUMAn issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoinEPSS 0.3%CVE-2024-54176MEDIUMIBM UrbanCode Deploy missing authenticationEPSS 0.3%CVE-2026-100876MEDIUMmathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenticationEPSS 0.3%CVE-2026-83252HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%