Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-65010HIGHMissing authorizations for admin panel password change in WODESYS WD-R608U routerEPSS 0.2%CVE-2025-55073MEDIUMMS Teams plugin OAuth allows editing arbitrary postsEPSS 0.2%CVE-2023-4516HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker tEPSS 0.2%CVE-2025-30040CRITICALMissing authentication in API returning request logs containing session IDsEPSS 0.2%CVE-2026-60600HIGHVulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version tEPSS 0.2%CVE-2023-25493MEDIUMA potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products EPSS 0.2%CVE-2026-75060HIGHIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP toolsEPSS 0.2%CVE-2026-6348CRITICALSimopro Technology|WinMatrix - Missing AuthenticationEPSS 0.2%CVE-2026-60765HIGHVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are EPSS 0.2%CVE-2025-55581HIGHD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. EPSS 0.2%CVE-2025-0129CRITICALPrisma Access Browser: Inappropriate control behavior in Prisma Access BrowserEPSS 0.2%CVE-2026-24259MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A succeEPSS 0.2%CVE-2025-54158HIGHMissing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local userEPSS 0.2%CVE-2026-1264HIGHIBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access ControlsEPSS 0.2%CVE-2026-4522MEDIUMMissing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affeEPSS 0.2%CVE-2024-55538MEDIUMSensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before buildEPSS 0.2%CVE-2025-64770HIGHMissing Authentication for ONVIF in iCam CamerasEPSS 0.2%CVE-2025-30041CRITICALMissing authentication in APIs returning statistical data along with session IDsEPSS 0.2%CVE-2023-52949MEDIUMMissing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent befoEPSS 0.2%CVE-2025-30039CRITICALMissing authentication in API returning a list of all active sessionsEPSS 0.2%