Falhas do tipo CWE-306

2.595 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2016-6541TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributesEPSS 1.1%CVE-2025-11942MEDIUM70mai X200 Pairing missing authenticationEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2024-39273CRITICALA firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP requeEPSS 1.1%CVE-2026-54130CRITICALM365 Copilot Information Disclosure VulnerabilityEPSS 1.1%CVE-2022-30230CRITICALA vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticEPSS 1.1%CVE-2020-15799A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT sEPSS 1.1%CVE-2016-6549Zizai Tech Nut allows for unauthenticated Bluetooth pairingEPSS 1.1%CVE-2022-29881MEDIUMA vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employEPSS 1.1%CVE-2025-7862MEDIUMTOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authenticationEPSS 1.1%CVE-2026-75854CRITICALArcadeDB Redis Wire-Protocol Plugin Missing AuthenticationEPSS 1.1%CVE-2022-45140CRITICALWAGO: Missing Authentication for Critical Function EPSS 1.1%CVE-2022-42785CRITICALWiesemann & Theis: Authentication bypass in Com-Server familyEPSS 1.1%CVE-2025-4268MEDIUMTOTOLINK A720R cstecgi.cgi missing authenticationEPSS 1.1%CVE-2025-41703HIGHPhoenix Contact: UPS Shutdown via Unauthenticated Modbus CommandEPSS 1.1%CVE-2020-36892CRITICALEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated Privilege EscalationEPSS 1.1%CVE-2021-3589An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can acEPSS 1.0%CVE-2025-48814HIGHRemote Desktop Licensing Service Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2023-33553CRITICALAn issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulEPSS 1.0%CVE-2021-1396CRITICALCisco Application Services Engine Unauthorized Access VulnerabilitiesEPSS 1.0%