Falhas do tipo CWE-306

2.599 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-22513MEDIUMdjangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources EPSS 0.8%CVE-2022-27623HIGHMissing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.EPSS 0.8%CVE-2026-84840MEDIUMtsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authenticationEPSS 0.8%CVE-2022-50790MEDIUMSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream DisclosureEPSS 0.8%CVE-2021-27395—A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versioEPSS 0.8%CVE-2023-6595HIGHWhatsUp Gold Unauthenticated Access to an API EndpointEPSS 0.8%CVE-2026-4312CRITICALDrangSoft|GCB/FCB Audit Software - Missing AuthenticationEPSS 0.8%CVE-2023-49617CRITICALMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-63508CRITICALMicrosoft Planetary Computer Pro Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2020-36894CRITICALEibiz i-Media Server Digital Signage 3.8.0 Unauthenticated User Creation VulnerabilityEPSS 0.8%CVE-2026-63455CRITICALAuthentication bypass via spoofed HTTP headers Orchestrator REST APIEPSS 0.8%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.8%CVE-2026-73125CRITICALEbyte NA111-M Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-24124HIGHDragonfly Manager Job API Allows Unauthenticated AccessEPSS 0.8%CVE-2024-2921CRITICALImproper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to tEPSS 0.8%CVE-2025-21524CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported verEPSS 0.8%CVE-2026-82967CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.8%CVE-2026-72593CRITICALdulldusk phpfm - Missing Authentication by Default Allows Full Filesystem AccessEPSS 0.8%CVE-2024-39773MEDIUMAn information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTEPSS 0.8%CVE-2026-7714MEDIUMcrocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authenticationEPSS 0.8%