Falhas do tipo CWE-306

2.599 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-5951HIGHDeep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service VulnerabilityEPSS 0.8%CVE-2023-38379—The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin passworEPSS 0.8%CVE-2022-22809—A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in aEPSS 0.8%CVE-2025-59358HIGHDenial of Service via Unauthorized Access to Chaos Mesh debugging serverEPSS 0.8%CVE-2025-55108CRITICALBMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code executionEPSS 0.8%CVE-2024-47138CRITICALmySCADA myPRO Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-77915CRITICALrConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.phpEPSS 0.8%CVE-2025-9574CRITICALMissing Authentication VulnerabilityEPSS 0.8%CVE-2026-84839MEDIUMtsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authenticationEPSS 0.8%CVE-2026-54103CRITICALU.S. GAO EPDS and CBCA EDS unauthenticated password changeEPSS 0.8%CVE-2026-9336MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.8%CVE-2018-25412CRITICALDelta Sql 1.8.2 Arbitrary File Upload via docs_upload.phpEPSS 0.8%CVE-2025-14567MEDIUMhaxxorsid Stock-Management-System employees missing authenticationEPSS 0.8%CVE-2026-91002MEDIUMstamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authenticationEPSS 0.8%CVE-2026-26944HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 0.8%CVE-2026-78239CRITICALXiiaozet LK100W Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2026-15192MEDIUMmettle sendportal APIv1 Webhooks mailjet missing authenticationEPSS 0.8%CVE-2026-4959MEDIUMOpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authenticationEPSS 0.8%CVE-2022-22526CRITICALMissing authentication for API in Carlo Gavazzi UWP 3.0 Car Park ServerEPSS 0.8%