Falhas do tipo CWE-306

2.584 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2020-36873HIGHAstak CM-818T3 Unauthenticated Configuration DisclosureEPSS 0.6%CVE-2026-40050CRITICALCrowdStrike LogScale Unauthenticated Path TraversalEPSS 0.6%CVE-2024-26011MEDIUMA missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.EPSS 0.6%CVE-2026-51937HIGHAn issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.javEPSS 0.6%CVE-2026-54460CRITICALOpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeoverEPSS 0.6%CVE-2026-86184CRITICALLara Dashboard before 1.3.0 Missing Authentication in screenshot-login RouteEPSS 0.6%CVE-2021-4461CRITICALSeeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication BypassEPSS 0.6%CVE-2023-2187MEDIUMOn Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WeEPSS 0.6%CVE-2024-1573MEDIUMMissing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.EPSS 0.6%CVE-2023-49115HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-86121CRITICALCua computer-server before 0.3.42 Unauthenticated RCE via Desktop ControlEPSS 0.6%CVE-2026-38059HIGHST Engineering iDirect iQ-Series Terminals Missing authentication for critical functionEPSS 0.6%CVE-2026-2165MEDIUMdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authenticationEPSS 0.6%CVE-2026-53869HIGHHermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket EndpointsEPSS 0.6%CVE-2026-73849CRITICALemlog allows unauthenticated reinstallation via `install.php?action=reinstall`.EPSS 0.6%CVE-2026-49362HIGHApache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue CreationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2023-22803HIGHCVE-2023-22803EPSS 0.6%CVE-2025-8558LOWInsider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated uEPSS 0.6%CVE-2024-32752HIGHJohnson Controls Software House iSTAR Configuration Utility (ICU) ToolEPSS 0.6%