Falhas do tipo CWE-306

2.628 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-50025MEDIUMMousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie stateEPSS 0.3%CVE-2024-56469MEDIUMIBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authenticationEPSS 0.3%CVE-2022-45190MEDIUMAn issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing EPSS 0.3%CVE-2024-48442MEDIUMIncorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows aEPSS 0.3%CVE-2026-77339MEDIUMProcess Compose: Browser DNS rebinding lets websites control local process-compose MCP toolsEPSS 0.3%CVE-2025-15509HIGHThe SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.EPSS 0.3%CVE-2026-57128MEDIUMPraisonAI: Unauthenticated Event Injection via SSE `/publish` EndpointEPSS 0.3%CVE-2023-25780MEDIUMStatus Internet Co.,Ltd. PowerBPM - Broken Access ControlEPSS 0.3%CVE-2025-3759HIGHMissing Authentication for Changing Device Configuration in WF2220EPSS 0.2%CVE-2026-32231HIGHZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload dataEPSS 0.2%CVE-2025-1495MEDIUMIBM Business Automation Workflow missing authenticationEPSS 0.2%CVE-2024-3219MEDIUMPure-Python fallback of socket.socketpair() doesn’t authenticate peer connectionEPSS 0.2%CVE-2026-73588HIGHDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnEPSS 0.2%CVE-2021-32453MEDIUMSITEL CAP/PRX information exposureEPSS 0.2%CVE-2026-57910CRITICALWatchGuard Agent improper authentication allows unauthenticated remote code executionEPSS 0.2%CVE-2026-12527MEDIUMA broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmwarEPSS 0.2%CVE-2026-47672MEDIUMepa4all-client: Unauthenticated REST API for Patient Record WritesEPSS 0.2%CVE-2022-48621MEDIUMVulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect EPSS 0.2%CVE-2025-54478HIGHUnauthenticated Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2021-23843HIGHLack of authentication mechanisms on the deviceEPSS 0.2%