Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-50608LOWAuthentication Vulnerability in NitroSense and PredatorSense SoftwareEPSS 0.2%CVE-2026-46555HIGHWhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationEPSS 0.2%CVE-2026-84400LOWCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2021-26278MEDIUMSensitive information leakage vulnerability in wifi moduleEPSS 0.2%CVE-2026-44211CRITICALCline Kanban Server has a Cross-Origin WebSocket Hijacking VulnerabilityEPSS 0.2%CVE-2022-50980MEDIUMMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via CANEPSS 0.2%CVE-2026-50604MEDIUMUnauthenticated Access Vulnerability in NitroSense and PredatorSense SoftwareEPSS 0.2%CVE-2025-30048MEDIUMUnauthenticated access to module configuration endpointEPSS 0.2%CVE-2025-30037HIGHMissing authentication in APIs allowing data retrieval and modificationEPSS 0.2%CVE-2025-44004HIGHUnauthenticated Channel Subscription Creation in Mattermost Confluence PluginEPSS 0.2%CVE-2021-21535HIGHDell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local unauthenticated attEPSS 0.2%CVE-2026-41477HIGHDeskflow: Local privilege escalation via unauthenticated IPCEPSS 0.2%CVE-2026-27846MEDIUMMissing authentication in Linksys MR9600, Linksys MX4200EPSS 0.2%CVE-2025-40816HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.2%CVE-2025-9214MEDIUMA missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or moEPSS 0.2%CVE-2025-32063MEDIUMEnabling SSH server on Infotainment ECUEPSS 0.2%CVE-2026-19397HIGHMissing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the hosEPSS 0.2%CVE-2026-61742CRITICALDBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL executionEPSS 0.2%CVE-2026-41047MEDIUMInformation leak via “diff” methods in qSnapperEPSS 0.2%CVE-2026-22727HIGHCloud Foundry unprotected internal endpointsEPSS 0.2%