Falhas do tipo CWE-306

2.630 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-60975HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affeEPSS 0.1%CVE-2026-22174MEDIUMOpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP ProbeEPSS 0.1%CVE-2026-19267MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2026-84403MEDIUMBotslab G980H Dashcams Missing Authentication for Critical FunctionEPSS 0.1%CVE-2026-24062HIGHInsufficient XPC Client validation leading to local privilege escalation in Arturia Software CenterEPSS 0.1%CVE-2026-12663HIGHControlFLASH ® – Improper Access ControlEPSS 0.1%CVE-2026-21767MEDIUMHCL BigFix Platform is affected by insufficient authenticationEPSS 0.1%CVE-2026-47122MEDIUMSparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injectionEPSS 0.1%CVE-2025-31963LOWHCL BigFix IVR is impacted by improper authentication and missing CSRF protectionEPSS 0.1%CVE-2025-47357HIGHMissing Authentication for Critical Function in SMSSEPSS 0.1%CVE-2026-24088HIGHMissing Authentication for Critical Function in BootEPSS 0.1%CVE-2025-48608MEDIUMIn isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead toEPSS 0.1%CVE-2026-24090HIGHMissing Authentication for Critical Function in HLOSEPSS 0.1%CVE-2026-7395HIGHAsset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to EPSS —CVE-2026-102362MEDIUMmall4j through 4.0 Missing Authentication in Product Review DeletionEPSS —CVE-2026-49994CRITICALBluehood: Missing authentication on Bluehood API routes when web auth is enabledEPSS —CVE-2026-102245MEDIUMMODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authenticationEPSS —CVE-2026-101077CRITICALNetcore NR289-GE boa_temp process_request missing authenticationEPSS —CVE-2026-102363MEDIUMmall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order NumberEPSS —CVE-2026-53988CRITICALDockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook EndpointsEPSS —