Falhas do tipo CWE-306

2.599 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2020-3333MEDIUMCisco Application Services Engine Software Unauthenticated Event Policies Update VulnerabilityEPSS 1.0%CVE-2025-36535CRITICALAutomationDirect MB-Gateway Missing Authentication for Critical FunctionEPSS 1.0%CVE-2022-41272CRITICALAn unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NeEPSS 1.0%CVE-2024-9164CRITICALMissing Authentication for Critical Function in GitLabEPSS 1.0%CVE-2026-12046CRITICALpgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code executionEPSS 1.0%CVE-2019-13549—Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected syEPSS 1.0%CVE-2014-125113CRITICALDell/Quest KACE K1000 Unauthenticated File Upload RCEEPSS 1.0%CVE-2022-44784HIGHAn issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the AxEPSS 1.0%CVE-2017-6873—A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulatEPSS 1.0%CVE-2024-28179CRITICALJupyter Server Proxy's Websocket Proxying does not require authenticationEPSS 1.0%CVE-2019-16004MEDIUMCisco Vision Dynamic Signage Director Authentication Bypass VulnerabilityEPSS 1.0%CVE-2025-27647CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users WitEPSS 1.0%CVE-2023-41187HIGHD-Link DAP-1325 HNAP Missing Authentication Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-43999CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executeEPSS 1.0%CVE-2022-44000CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbEPSS 1.0%CVE-2023-39466MEDIUMTriangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure VulnerabilityEPSS 1.0%CVE-2021-26928MEDIUMBIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which mEPSS 1.0%CVE-2026-21992CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services ManagEPSS 1.0%CVE-2026-64921HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2025-34218CRITICALVasion Print (formerly PrinterLogic) Exposed Internal Docker InstanceEPSS 1.0%