Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-34111CRITICALTiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCEEPSS 2.2%CVE-2026-2624CRITICALAuthentication Bypass in ePati's Antikor NGFWEPSS 2.2%CVE-2025-34119HIGHEasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43EPSS 2.2%CVE-2018-0181HIGHCisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent Software Redis Server Unauthenticated Access VulnerabilityEPSS 2.2%CVE-2014-125124CRITICALPandora FMS <= 5.0RC1 Anyterm Unauthenticated Command InjectionEPSS 2.1%CVE-2020-7389MEDIUMSage X3 Syracuse Missing Authentication for Critical Function in Developer EnvironmentEPSS 2.1%CVE-2026-56270HIGHFlowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod EndpointEPSS 2.0%CVE-2017-3217CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / resellerEPSS 2.0%CVE-2024-21855CRITICALA lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arEPSS 2.0%CVE-2023-39457CRITICALTriangle MicroWorks SCADA Data Gateway Missing Authentication VulnerabilityEPSS 2.0%CVE-2023-2231CRITICALMAXTECH MAX-G866ac Remote Management missing authenticationEPSS 2.0%CVE-2019-18572HIGHThe RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper AuthenticatioEPSS 2.0%CVE-2020-7589A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker readinEPSS 2.0%CVE-2026-61808CRITICALLightRAG: Missing Authentication for Critical API Functions in Default ConfigurationEPSS 2.0%CVE-2015-7559LOWIt was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker loEPSS 2.0%CVE-2014-9197Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical FunctionEPSS 2.0%CVE-2025-34110CRITICALColoradoFTP Server <= 1.3 Build 8 Path Traversal Information DisclosureEPSS 1.9%CVE-2022-39412HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affEPSS 1.9%CVE-2026-58127CRITICALPACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP ServiceEPSS 1.9%CVE-2022-25251CRITICALPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 1.9%