Falhas do tipo CWE-306

2.604 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-21007HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.7%CVE-2024-3279CRITICALImproper Access Control in mintplex-labs/anything-llmEPSS 0.6%CVE-2020-36871HIGHESCAM QD-900 Unauthenticated Configuration DisclosureEPSS 0.6%CVE-2025-53378HIGHA missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticaEPSS 0.6%CVE-2025-12003HIGHA path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of thEPSS 0.6%CVE-2025-8610CRITICALAOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-62645CRITICALA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be usEPSS 0.6%CVE-2026-40702CRITICALEVoke Systems EVoke CSMS Missing Authentication for Critical FunctionEPSS 0.6%CVE-2025-9254CRITICALUniong|WebITR - Missing AuthenticationEPSS 0.6%CVE-2025-8611CRITICALAOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-40884CRITICALgoshs: Empty-username SFTP password authentication bypass in goshsEPSS 0.6%CVE-2026-27012CRITICALUnauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.phpEPSS 0.6%CVE-2025-53072CRITICALVulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that areEPSS 0.6%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.6%CVE-2025-10452CRITICALGotac|Statistical Database System - Missing AuthenticationEPSS 0.6%CVE-2022-34908HIGHAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some fEPSS 0.6%CVE-2026-85671HIGHQAnything 2.0.0 Unauthenticated Cross-User File DisclosureEPSS 0.6%CVE-2026-65956CRITICALKubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRFEPSS 0.6%CVE-2026-21446HIGHBagisto Missing Authentication on Installer API EndpointsEPSS 0.6%CVE-2026-15706CRITICALMissing Authentication for Critical Function in Management API in Baylan Water Meters's BMSEPSS 0.6%