Falhas do tipo CWE-306

2.576 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2023-54352CRITICALWordPress Seotheme Remote Code Execution UnauthenticatedEPSS 0.6%CVE-2026-50242CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via diEPSS 0.6%CVE-2026-13007HIGHInsecure Public Caching on REST API Endpoints in Tenable Identity ExposureEPSS 0.6%CVE-2023-22650HIGHRancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderEPSS 0.6%CVE-2026-4767CRITICALImproper Access Control in TR7's WAF-ASPEPSS 0.6%CVE-2022-35136MEDIUMBoodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.EPSS 0.6%CVE-2026-93839CRITICALLightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket EndpointEPSS 0.6%CVE-2025-5906MEDIUMcode-projects Laundry System data missing authenticationEPSS 0.6%CVE-2023-5881HIGHUnauthenticated access permitted to web interface page "Garage Door Control Module Setup"EPSS 0.6%CVE-2026-1729CRITICALAdForest <= 6.0.12 - Authentication BypassEPSS 0.6%CVE-2023-26571HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.6%CVE-2024-5952MEDIUMDeep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service VulnerabilityEPSS 0.6%CVE-2026-55605MEDIUM@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP EndpointEPSS 0.6%CVE-2025-41651CRITICALWeidmueller: Missing Authentication Vulnerability in Industrial Ethernet SwitchesEPSS 0.6%CVE-2022-38057MEDIUMWordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerabilityEPSS 0.6%CVE-2026-22788HIGHWebErpMesv2 allows unauthenticated API AccessEPSS 0.6%CVE-2023-32680MEDIUMMissing SQL permissions check in metabaseEPSS 0.6%CVE-2026-57475MEDIUMDeloitte AI Assist for Customer unauthenticated configuration writeEPSS 0.6%CVE-2020-36873HIGHAstak CM-818T3 Unauthenticated Configuration DisclosureEPSS 0.6%CVE-2026-40050CRITICALCrowdStrike LogScale Unauthenticated Path TraversalEPSS 0.6%