Falhas do tipo CWE-306

2.594 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-28771Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send maliciouEPSS 1.1%CVE-2025-21623HIGHClipBucket V5 Unauthenticated Template Directory Update to Denial-of-ServiceEPSS 1.1%CVE-2018-14796Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be usedEPSS 1.1%CVE-2019-18230Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticatEPSS 1.1%CVE-2020-10605Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.EPSS 1.1%CVE-2023-27747HIGHBlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access seEPSS 1.1%CVE-2023-21743MEDIUMMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2023-36851MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary filesEPSS 1.1%KEVCVE-2022-38168CRITICALBroken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackEPSS 1.1%CVE-2025-3699CRITICALMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A EPSS 1.1%CVE-2025-26339CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 aEPSS 1.1%CVE-2025-26344CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to versionEPSS 1.1%CVE-2025-26347CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.EPSS 1.1%CVE-2025-26341CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2EPSS 1.1%CVE-2025-26345CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.EPSS 1.1%CVE-2025-26342CRITICALA CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2EPSS 1.1%CVE-2021-20998CRITICALWAGO: Managed Switches: Unauthorized creation of user accountsEPSS 1.1%CVE-2022-2242CRITICALKUKA V/KSS WoV SH access control vulnerabilityEPSS 1.1%CVE-2023-23453CRITICALMissing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to EPSS 1.1%CVE-2023-23452CRITICALMissing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to EPSS 1.1%