Falhas do tipo CWE-306

2.627 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-25770HIGHInsufficient authentication in upgrade flowEPSS 0.3%CVE-2025-27256HIGHMissing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to EPSS 0.3%CVE-2026-83252HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.3%CVE-2025-13778HIGHDevice Reboot ControlEPSS 0.3%CVE-2025-36756MEDIUMDevice Takeover vulnerability in SolaX CloudEPSS 0.3%CVE-2026-81238HIGHDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unautheEPSS 0.3%CVE-2025-10746MEDIUMIntegrate Dynamics 365 CRM <= 1.0.9 - Missing AuthorizationEPSS 0.3%CVE-2026-55837MEDIUMdbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensEPSS 0.3%CVE-2026-60322MEDIUMVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported vEPSS 0.3%CVE-2026-42341CRITICALFOSSBilling has an unauthenticated payment bypass via IPN callback forgeryEPSS 0.3%CVE-2026-60682MEDIUMVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that isEPSS 0.3%CVE-2025-0256MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosureEPSS 0.3%CVE-2019-25678HIGHC4G BLIS 3.4 SQL Injection via users_select.phpEPSS 0.3%CVE-2026-76902MEDIUMCordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`EPSS 0.3%CVE-2026-61247MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.3%CVE-2025-11198HIGHSecurity Director Policy Enforcer: An unrestricted API allows a network-based unauthenticated attacker to deploy malicious vSRX images to VMWare NSX ServerEPSS 0.3%CVE-2026-22192HIGHVoltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorageEPSS 0.3%CVE-2026-49174MEDIUMDNS Client Tampering VulnerabilityEPSS 0.3%CVE-2026-73842CRITICALOpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutationEPSS 0.3%