Falhas do tipo CWE-306

2.629 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-23293HIGHNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.2%CVE-2024-31684LOWIncorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fEPSS 0.2%CVE-2024-47555HIGHMissing Authentication - User & System ConfigurationEPSS 0.2%CVE-2023-47232MEDIUMWordPress WP Affiliate Disclosure plugin <= 1.2.6 - Broken Access Control + CSRF vulnerabilityEPSS 0.2%CVE-2026-78306HIGHDJI Drone Bluetooth Interface Unauthenticated DUML Command ExecutionEPSS 0.2%CVE-2025-64056MEDIUMFile upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the fiEPSS 0.2%CVE-2023-0463HIGHThe force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022EPSS 0.2%CVE-2020-12484MEDIUMWhen using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprisEPSS 0.2%CVE-2026-48106HIGHArc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peerEPSS 0.2%CVE-2026-57112HIGHPraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered toolsEPSS 0.2%CVE-2025-3646MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share APIEPSS 0.2%CVE-2025-13870LOWUnauthorized access and subscription vulnerability in BoardsEPSS 0.2%CVE-2026-85478LOWCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-3758HIGHExposure of Device Configuration without Authentication in WF2220EPSS 0.2%CVE-2025-11130HIGHiHongRen pptp-vpn XPC Service HelperTool.m shouldAcceptNewConnection missing authenticationEPSS 0.2%CVE-2025-40817HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.2%CVE-2026-84696CRITICALPhison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique CommandsEPSS 0.2%CVE-2025-47870MEDIUMTeam invite ID leaked to team admin with no member invite privilegesEPSS 0.2%CVE-2024-39364HIGHAdvantech ADAM-5630 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2026-10054HIGHIn affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shellEPSS 0.2%