Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-35865HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication EPSS 1.9%CVE-2026-26235HIGHJUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing AuthenticationEPSS 1.9%CVE-2026-58126CRITICALPACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP ServiceEPSS 1.8%CVE-2021-20198A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift ConEPSS 1.8%CVE-2026-4810CRITICALRemote Code Execution in Google Agent Development Kit (ADK)EPSS 1.8%CVE-2024-8321MEDIUMMissing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attaEPSS 1.8%CVE-2025-34120HIGHLimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup PayloadEPSS 1.8%CVE-2021-32800HIGHBypass of Two Factor Authentication in Nextcloud serverEPSS 1.8%CVE-2023-46819MEDIUMApache OFBiz: Execution of Solr plugin queries without authenticationEPSS 1.8%CVE-2022-39425HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 1.8%CVE-2018-4840A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 EEPSS 1.8%CVE-2019-1876MEDIUMCisco Wide Area Application Services Software HTTPS Proxy Authentication Bypass VulnerabilityEPSS 1.8%CVE-2022-34321HIGHApache Pulsar: Improper Authentication for Pulsar Proxy Statistics EndpointEPSS 1.8%CVE-2020-10282CRITICALRVD#3316: No authentication in MAVLink protocolEPSS 1.8%CVE-2022-34858CRITICALWordPress OAuth 2.0 client for SSO plugin <= 1.11.3 - Authentication Bypass vulnerabilityEPSS 1.8%CVE-2021-34538Apache Hive Security vulnerability in Hive with UDFsEPSS 1.8%CVE-2014-125126CRITICALSimple E-Document Arbitrary File Upload RCEEPSS 1.7%CVE-2026-75791HIGHAuthentication bypass vulnerabilityEPSS 1.7%CVE-2022-27169HIGHAn information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16EPSS 1.7%CVE-2022-45481CRITICALThe default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with noEPSS 1.7%