Falhas do tipo CWE-306

2.628 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-6895MEDIUMInsecure Account Profile ManagementEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%CVE-2026-3194LOWChia Blockchain RPC Server Master Passphrase get_private_key missing authenticationEPSS 0.2%CVE-2022-3312MEDIUMInsufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass manEPSS 0.2%CVE-2025-68716HIGHKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configuEPSS 0.2%CVE-2023-48426CRITICALChromecast Bootloader & Kernel-level code-execution including compromise of user-dataEPSS 0.2%CVE-2025-53034MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.2%CVE-2024-2104HIGHJBL: Improper BLE security configurations and lack of authentication on the device's GATT serverEPSS 0.2%CVE-2023-6949MEDIUMA Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 EPSS 0.2%CVE-2026-6017HIGHMissing Authentication for Critical Function in KAON PG5298EPSS 0.2%CVE-2025-9312CRITICALImproper Certificate-Based Authentication Enforcement in Multiple WSO2 ProductsEPSS 0.2%CVE-2026-24177HIGHNVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of thEPSS 0.2%CVE-2025-1272HIGHKernel: secure boot does not automatically enable kernel lockdownEPSS 0.2%CVE-2025-5719MEDIUMThe wallet has an authentication bypass vulnerability that allows access to specific pages.EPSS 0.2%CVE-2026-8706MEDIUMSensitive user data could be leaked to other applications through Reader modeEPSS 0.2%CVE-2026-71568MEDIUMBMCtest exposes Ironic without authentication and TLS during the testEPSS 0.2%CVE-2025-14038HIGHEDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an atEPSS 0.2%CVE-2025-64307HIGHBrightpick Mission Control / Internal Logic Control Missing Authentication for Critical FunctionEPSS 0.2%CVE-2024-45483HIGHMissing GRUB password in B&R APROLEPSS 0.2%CVE-2026-1920MEDIUMBooktics <= 1.0.16 - Missing Authorization to Addon Plugin InstallationEPSS 0.2%