Falhas do tipo CWE-306

2.560 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-57432CRITICALBlackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remoteEPSS 0.6%CVE-2024-4332CRITICALImproper Authentication in Tripwire Enterprise 9.1.0 APIsEPSS 0.6%CVE-2024-3701CRITICALImproper Authentication in com.transsion.kolun.aiserviceEPSS 0.6%CVE-2026-26288CRITICALEveron api.everon.io Missing Authentication for Critical FunctionEPSS 0.6%CVE-2023-53968CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase AccountEPSS 0.6%CVE-2023-5716CRITICALASUS Armoury Crate - Arbitrary File WriteEPSS 0.6%CVE-2023-38422HIGHWalchem Intuition Missing Authentication for Critical Function EPSS 0.6%CVE-2023-21979HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.6%CVE-2025-34069CRITICALGFI Kerio Control GFIAgent Authentication Bypass via Proxy ForwardingEPSS 0.6%CVE-2026-58375HIGHJimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/exportEPSS 0.6%CVE-2022-50595CRITICALAdvantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCEEPSS 0.6%CVE-2026-14162CRITICALAdvantech|Hospital Quering Management - Missing AuthenticationEPSS 0.6%CVE-2022-50592CRITICALAdvantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCEEPSS 0.6%CVE-2023-28470MEDIUMIn Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.EPSS 0.6%CVE-2025-58083CRITICALGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%CVE-2021-4469HIGHDenver SHO-110 IP Camera Unauthenticated Snapshot AccessEPSS 0.6%CVE-2022-41629HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, whichEPSS 0.6%CVE-2026-86808MEDIUMmoltis-org moltis vault.rs vault_recovery_handler missing authenticationEPSS 0.6%CVE-2024-8053HIGHImproper Authentication in open-webui/open-webuiEPSS 0.6%