Falhas do tipo CWE-306

2.603 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-5632MEDIUMassafelovic gpt-researcher HTTP REST API Endpoint missing authenticationEPSS 0.7%CVE-2026-15491MEDIUMRafyMrX TOKO-ONLINE-ROTI missing authenticationEPSS 0.7%CVE-2026-82919MEDIUMcu silicon edit Endpoint views.py create_app missing authenticationEPSS 0.7%CVE-2026-4562MEDIUMMacCMS Timming API Endpoint Timming.php weak authenticationEPSS 0.7%CVE-2026-6582MEDIUMTransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authenticationEPSS 0.7%CVE-2026-18810MEDIUMH3C NX15 networkSetup missing authenticationEPSS 0.7%CVE-2026-7042MEDIUM666ghj MiroFish REST API Endpoint __init__.py create_app missing authenticationEPSS 0.7%CVE-2026-13546MEDIUMFeehi CMS REST API Endpoint articles missing authenticationEPSS 0.7%CVE-2026-6129MEDIUMzhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authenticationEPSS 0.7%CVE-2026-90504MEDIUMvvbbnn00 WARP-Clash-API authorized missing authenticationEPSS 0.7%CVE-2026-5000MEDIUMPromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authenticationEPSS 0.7%CVE-2026-93559MEDIUMForget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authenticationEPSS 0.7%CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-90579MEDIUMcheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authenticationEPSS 0.7%CVE-2026-45083CRITICALGoobi viewer: Unauthenticated Solr Streaming Expression ProxyEPSS 0.7%CVE-2022-29877—A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.0EPSS 0.7%CVE-2026-4640HIGHGalaxy Software Services|Vitals ESP - Missing AuthenticationEPSS 0.7%CVE-2021-4468HIGHPLANEX CS-QP50F-ING2 Smart Camera Remote Configuration DisclosureEPSS 0.7%CVE-2026-31071CRITICALAPI endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers caEPSS 0.7%