Falhas do tipo CWE-306

2.599 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2020-14140HIGHWhen Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerabilEPSS 1.0%CVE-2020-10754MEDIUMIt was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when cEPSS 1.0%CVE-2020-23648HIGHAsus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can changeEPSS 1.0%CVE-2016-10364—With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL servEPSS 1.0%CVE-2026-63722HIGHICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpEPSS 1.0%CVE-2023-22441HIGHMissing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alteEPSS 1.0%CVE-2026-25938CRITICALFUXA Unauthenticated Remote Code Execution in Node-RED IntegrationEPSS 1.0%CVE-2023-53964HIGHSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset VulnerabilityEPSS 1.0%CVE-2024-36445CRITICALSwissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.EPSS 1.0%CVE-2023-53771CRITICALMiniDVBLinux 5.4 Unauthenticated Root Password Change via System SetupEPSS 1.0%CVE-2026-0625CRITICALD-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration EndpointEPSS 1.0%CVE-2026-57131CRITICALpraisonai: Jobs API exposes agent-execution endpoints with no authenticationEPSS 1.0%CVE-2025-34224CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Device ModificationEPSS 1.0%CVE-2026-26333CRITICALCalero VeraSMART < 2022 R1 .NET Remoting Arbitrary File Read Leading to ViewState RCEEPSS 1.0%CVE-2025-5095CRITICALBurk Technology ARC Solo Missing Authentication for Critical FunctionEPSS 1.0%CVE-2023-25589CRITICALUnauthenticated Arbitrary User Creation Leads to Complete System CompromiseEPSS 1.0%CVE-2023-1096CRITICALSnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated EPSS 1.0%CVE-2026-57206HIGHSimpleChat plugin validation endpoints missing authentication and authorizationEPSS 1.0%CVE-2025-34414CRITICALEntrust Instant Financial Issuance (IFI) Legacy Remoting Service .NET Remoting RCEEPSS 1.0%CVE-2023-6942HIGHMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 VeEPSS 0.9%