Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-0247MEDIUMPrisma Access Agent Endpoint DLP: Authorization Bypass VulnerabilitiesEPSS 0.2%CVE-2021-26280HIGHPermission bypass vulnerability in permission manager moduleEPSS 0.2%CVE-2026-11535CRITICALAn unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to thEPSS 0.2%CVE-2026-9045HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise foEPSS 0.1%CVE-2026-42283HIGHDevSpace UI Server WebSocket CheckOrigin does not validate sourceEPSS 0.1%CVE-2026-12763MEDIUMLangflow is vulnerable to authentication bypass and insufficient session expirationEPSS 0.1%CVE-2026-46685MEDIUMRustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on consoleEPSS 0.1%CVE-2026-60569MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0EPSS 0.1%CVE-2024-45355MEDIUMXiaomi phone framework has unauthorized access vulnerabilityEPSS 0.1%CVE-2024-9062HIGHmacOS Archify: Local Privilege EscalationEPSS 0.1%CVE-2026-70806HIGHVulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.1%CVE-2026-92254MEDIUMWatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTLEPSS 0.1%CVE-2026-70693MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.1%CVE-2025-15567MEDIUMInsufficient protection mechanisms in the Health Module may lead to partial information disclosure.EPSS 0.1%CVE-2025-30650HIGHJunos OS: Privileged local user can gain access to a Linux-based FPC as rootEPSS 0.1%CVE-2026-6511MEDIUMDuring an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for WindowsEPSS 0.1%CVE-2025-41686HIGHImproper File Permissions Allow Local Privilege EscalationEPSS 0.1%CVE-2026-60902HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affectEPSS 0.1%CVE-2026-70711LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.1%CVE-2019-25483HIGHComtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell EscapeEPSS 0.1%