Falhas do tipo CWE-306

2.628 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-9815HIGHalaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authenticationEPSS 0.3%CVE-2024-57055MEDIUMServer-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain servEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.3%CVE-2026-13306MEDIUMAutel MaxiCharger AC Elite Home USB Authentication Bypass VulnerabilityEPSS 0.3%CVE-2026-77974HIGHSoftish C6 Ear Camera and EarVision Android Application Missing authentication for critical functionEPSS 0.3%CVE-2025-1754MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.3%CVE-2025-0275MEDIUMHCL BigFix Mobile 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2026-86486LOWIn JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blankEPSS 0.3%CVE-2026-18185HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2025-0274MEDIUMHCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2026-94455HIGHUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API keyEPSS 0.3%CVE-2026-60574MEDIUMVulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affecEPSS 0.3%CVE-2024-6347MEDIUMUnauthorized access to ECU functionalityEPSS 0.3%CVE-2026-62474MEDIUMVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versionEPSS 0.3%CVE-2026-81455HIGHDell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An uEPSS 0.3%CVE-2026-59148HIGHMockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftEPSS 0.3%CVE-2026-1919MEDIUMBooktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpointsEPSS 0.3%CVE-2025-48572HIGHIn multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to locaEPSS 0.3%KEVCVE-2025-7706MEDIUMImproper Access Control in TUBITAK BILGEM's LiderahenkEPSS 0.3%CVE-2026-50025MEDIUMMousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie stateEPSS 0.3%