Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-32752HIGHJohnson Controls Software House iSTAR Configuration Utility (ICU) ToolEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2024-41988CRITICALMissing Authentication for Critical Function vulnerability in TEM Opera Plus FM Family TransmitterEPSS 0.6%CVE-2018-25332CRITICALGitBucket 4.23.1 Unauthenticated Remote Code ExecutionEPSS 0.6%CVE-2026-42074CRITICALOpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` InputEPSS 0.6%CVE-2026-18941HIGHFeast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authenticationEPSS 0.6%CVE-2026-25116HIGHRuntipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path TraversalEPSS 0.6%CVE-2026-35546CRITICALAnviz Products Missing Authentication for Critical FunctionEPSS 0.6%CVE-2021-47933CRITICALWordPress MStore API 2.0.6 Arbitrary File UploadEPSS 0.6%CVE-2022-41271CRITICALAn unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PEPSS 0.6%CVE-2024-6422CRITICALPepperl+Fuchs: OIT Products can be manipulated via unintended Telnet accessEPSS 0.6%CVE-2024-6981CRITICALOMNTEC Proteus Tank Monitoring Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2022-20861CRITICALCisco Nexus Dashboard Unauthorized Access VulnerabilitiesEPSS 0.6%CVE-2026-54061CRITICALDgraph Alpha group stores can be replaced via unauthenticated external snapshot importEPSS 0.6%CVE-2023-6221HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2020-5589—SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SPEPSS 0.6%CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2024-7940HIGHThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.6%