Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2020-6287CRITICALSAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows anEPSS 94.7%KEVCVE-2025-4008HIGHArbitrary Command Injection in Smartbedded MeteoBridgeEPSS 93.7%KEVCVE-2023-36846MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 93.5%KEVCVE-2021-44077CRITICALZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unEPSS 93.3%KEVCVE-2024-5910CRITICALExpedition: Missing Authentication Leads to Admin Account TakeoverEPSS 91.8%KEVCVE-2024-11680CRITICALProjectSend Unauthenticated Configuration ModificationEPSS 91.7%KEVCVE-2020-3952CRITICALUnder certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)EPSS 90.4%KEVCVE-2025-61757CRITICALVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affectEPSS 88.6%KEVCVE-2026-24423CRITICALSmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIEPSS 88.2%KEVCVE-2022-26143CRITICALThe TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers toEPSS 87.3%KEVCVE-2024-51567CRITICALupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication andEPSS 86.6%KEVCVE-2021-45232security vulnerability on unauthorized access.EPSS 86.3%CVE-2023-36847MEDIUMJunos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 85.4%KEVCVE-2022-24990CRITICALTerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/aEPSS 83.6%KEVCVE-2021-25094Tatsu < 3.3.12 - Unauthenticated RCEEPSS 83.4%CVE-2023-21931HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 82.3%CVE-2021-33543CRITICALUDP Technology/Geutebrück camera devices: Authentication BypassEPSS 81.3%CVE-2014-9195Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical FunctionEPSS 80.7%CVE-2021-1499MEDIUMCisco HyperFlex HX Data Platform File Upload VulnerabilityEPSS 80.4%CVE-2023-27532HIGHVulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. ThisEPSS 77.6%KEV