Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-60251MEDIUMUnitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.EPSS 0.2%CVE-2025-12941MEDIUMDenial of Service Vulnerability in NETGEAR C6220 and C6230EPSS 0.2%CVE-2026-42289HIGHChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege EscalationEPSS 0.2%CVE-2025-9160HIGHRockwell Automation CompactLogix® 5480 Code Execution VulnerabilityEPSS 0.2%CVE-2018-25225HIGHSIPP 3.3 Stack-Based Buffer Overflow via Configuration FileEPSS 0.2%CVE-2024-54013HIGHAuthentication BypassEPSS 0.2%CVE-2023-32460HIGH Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially eEPSS 0.2%CVE-2025-62287MEDIUMVulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported verEPSS 0.2%CVE-2018-25224HIGHPMS 0.42 Stack-Based Buffer Overflow via Configuration FileEPSS 0.2%CVE-2026-42312MEDIUMpyload-ng: non-admin SETTINGS users can disable outbound TLS peer verificationEPSS 0.2%CVE-2026-12910MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.2%CVE-2018-25259HIGHTerminal Services Manager 3.1 Buffer Overflow SEHEPSS 0.2%CVE-2020-12491MEDIUMFramework Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-35342MEDIUMCertain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, EPSS 0.2%CVE-2021-26264MEDIUMEmerson DeltaV Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-15481MEDIUMNotification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data DisclosureEPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.2%CVE-2026-11838MEDIUMImproper Authorization in Yordam Informatics' Library Reservation SystemEPSS 0.2%CVE-2026-85981MEDIUMUnauthenticated Localhost Admin Panel in Auth0 AD/LDAP ConnectorEPSS 0.2%CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.2%