Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-12444MEDIUMIncorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in sEPSS 0.2%CVE-2025-30039CRITICALMissing authentication in API returning a list of all active sessionsEPSS 0.2%CVE-2026-55529MEDIUMPraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP serverEPSS 0.2%CVE-2025-15515MEDIUMThe authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a loEPSS 0.2%CVE-2025-10991HIGHRoot Access via UARTEPSS 0.2%CVE-2026-96455HIGHReachy Mini daemon allows unauthenticated remote code execution through the app installation endpointEPSS 0.2%CVE-2025-62674HIGHMissing Authentication for RTSP in iCam CamerasEPSS 0.2%CVE-2020-9062—Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2026-81441MEDIUMDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An EPSS 0.2%CVE-2024-22449MEDIUM Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileEPSS 0.2%CVE-2026-60884MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.2%CVE-2026-11238MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicEPSS 0.2%CVE-2026-6369MEDIUMExposed Session Token in canonical-livepatch client snapEPSS 0.2%CVE-2024-39707MEDIUMInsyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could leEPSS 0.2%CVE-2026-16646MEDIUMPanKM - Critical - Unsupported - SA-CONTRIB-2026-083EPSS 0.2%CVE-2026-42095MEDIUMbookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.EPSS 0.2%CVE-2026-59913HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulneraEPSS 0.2%CVE-2020-12492LOWWifi information acquisition vulnerability in Framework ServicesEPSS 0.2%CVE-2025-67780MEDIUMSpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gREPSS 0.2%CVE-2026-32041HIGHOpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth BootstrapEPSS 0.2%