Falhas do tipo CWE-306

2.563 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-41629HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, whichEPSS 0.6%CVE-2024-8053HIGHImproper Authentication in open-webui/open-webuiEPSS 0.6%CVE-2026-90504MEDIUMvvbbnn00 WARP-Clash-API authorized missing authenticationEPSS 0.6%CVE-2025-53938MEDIUMWeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpointsEPSS 0.6%CVE-2024-45276HIGHMB connect line/Helmholz: tmp directory exposed via webserviceEPSS 0.6%CVE-2021-32709MEDIUMCreation of order credits was not validated by acl in admin ordersEPSS 0.6%CVE-2025-13510CRITICALIskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiyEPSS 0.6%CVE-2022-3738MEDIUMWAGO: Missing authentication for config export functionality in multiple productsEPSS 0.6%CVE-2022-45433LOWSome Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall acEPSS 0.6%CVE-2023-22072CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected EPSS 0.6%CVE-2024-35293CRITICALSchneider Elektronik Series 700 prone to missing authentication for critical reset functionEPSS 0.6%CVE-2023-30744HIGHImproper access control during application start-up in SAP AS NetWeaver JAVA.EPSS 0.6%CVE-2026-9051CRITICALAuthentication Bypass Vulnerability in NI SystemLink EnterpriseEPSS 0.6%CVE-2026-70352CRITICALAzure AI Language Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2024-45049HIGHNix Hydra Missing authentication when triggering evaluationsEPSS 0.6%CVE-2026-86242HIGHUnauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked BuildsEPSS 0.6%CVE-2024-12511HIGHSMB/FTP Address Book Scan Pass-back attackEPSS 0.6%CVE-2026-56346MEDIUMAVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php EndpointEPSS 0.6%CVE-2025-59097CRITICALUnauthenticated SOAP API in dormakaba access managerEPSS 0.6%