Falhas do tipo CWE-306

2.599 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-22526CRITICALMissing authentication for API in Carlo Gavazzi UWP 3.0 Car Park ServerEPSS 0.8%CVE-2017-6872—A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 2EPSS 0.8%CVE-2024-40717HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updaEPSS 0.8%CVE-2026-90513MEDIUMsimalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authenticationEPSS 0.8%CVE-2026-47281CRITICALVisual Studio Code Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-1775HIGHMissing Authentication for Critical Function in Labkotec LID-3300IPEPSS 0.8%CVE-2026-87924MEDIUMRizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authenticationEPSS 0.8%CVE-2026-86293MEDIUMSourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authenticationEPSS 0.8%CVE-2025-34071CRITICALGFI Kerio Control Unsigned System Image Upload Root Code ExecutionEPSS 0.8%CVE-2026-56262MEDIUMCrawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API ServerEPSS 0.8%CVE-2026-82472HIGHDocumenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdfEPSS 0.8%CVE-2024-22212CRITICALNextcloud global site selector authentication bypassEPSS 0.8%CVE-2026-25775CRITICALSenseLive X3050 Missing authentication for critical functionEPSS 0.8%CVE-2026-88018CRITICALrclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassEPSS 0.8%CVE-2026-57139CRITICALPraisonAI MCPServer exposes unauthenticated HTTP tools/callEPSS 0.8%CVE-2023-51947CRITICALImproper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types EPSS 0.8%CVE-2023-27497CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)EPSS 0.8%CVE-2023-22069CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%CVE-2026-85636MEDIUMjofpin trape Login Endpoint stats.py missing authenticationEPSS 0.8%CVE-2022-30229HIGHA vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticEPSS 0.7%