Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-33788HIGHJunos OS Evolved: Local, authenticated attacker can gain privileged access to FPCsEPSS 0.2%CVE-2025-12436MEDIUMPolicy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extensioEPSS 0.2%CVE-2023-52947MEDIUMMissing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3EPSS 0.2%CVE-2026-45610MEDIUMWWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FAEPSS 0.2%CVE-2026-24229HIGHNVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or EPSS 0.2%CVE-2025-58318MEDIUMDIAView - Authentication Bypass VulnerabilityEPSS 0.2%CVE-2024-2860HIGHThe PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker EPSS 0.2%CVE-2025-23356HIGHNVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code executEPSS 0.2%CVE-2026-60596LOWVulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version EPSS 0.2%CVE-2024-12957HIGHA file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 SEPSS 0.2%CVE-2025-14058LOWA potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical accEPSS 0.2%CVE-2023-5935HIGHMissing authentication for local web interface in Arc before v1.6.0EPSS 0.2%CVE-2025-47272MEDIUMPhoenixCart Vulnerable to Account Deletion Without Password ConfirmationEPSS 0.2%CVE-2026-94540HIGHDesktopSMS 1.11.0 Unauthorized Access via Local ServiceEPSS 0.2%CVE-2026-76137MEDIUMMissing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a rEPSS 0.2%CVE-2026-39848MEDIUMDockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database ManipulationEPSS 0.2%CVE-2024-45356HIGHXiaomi phone framework has unauthorized access vulnerabilityEPSS 0.2%CVE-2026-60595MEDIUMVulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The suppoEPSS 0.2%CVE-2026-60712MEDIUMVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.2%CVE-2026-54776MEDIUMCoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgradeEPSS 0.2%