Falhas do tipo CWE-306

2.605 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-47396CRITICALPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unsetEPSS 0.6%CVE-2026-6274CRITICALAuthentication Bypass in DTS Electronics' Redline WR3200EPSS 0.6%CVE-2026-57140CRITICALPraisonAI AgentOS exposes unauthenticated agent listing and invocationEPSS 0.6%CVE-2026-92805CRITICALUVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation WizardEPSS 0.6%CVE-2026-41930CRITICALVvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdminEPSS 0.6%CVE-2026-2754HIGHNavtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated rEPSS 0.6%CVE-2026-62327CRITICAL9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/statsEPSS 0.6%CVE-2026-82473HIGHKubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task EndpointsEPSS 0.6%CVE-2022-1070HIGHCHANNEL ACCESSIBLE BY NON-ENDPOINT CWE-300EPSS 0.6%CVE-2024-8053HIGHImproper Authentication in open-webui/open-webuiEPSS 0.6%CVE-2025-57432CRITICALBlackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remoteEPSS 0.6%CVE-2018-25134CRITICALSynaccess netBooter NP-02x/NP-08x 6.8 Authentication Bypass via webNewAcct.cgiEPSS 0.6%CVE-2024-4332CRITICALImproper Authentication in Tripwire Enterprise 9.1.0 APIsEPSS 0.6%CVE-2024-3701CRITICALImproper Authentication in com.transsion.kolun.aiserviceEPSS 0.6%CVE-2023-53968CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase AccountEPSS 0.6%CVE-2026-27595CRITICALParse Dashboard has incomplete authentication on AI Agent endpointEPSS 0.6%CVE-2026-34741HIGHCombodo iTop: Authentication bypass in exec.php allows PHP file executionEPSS 0.6%CVE-2023-38422HIGHWalchem Intuition Missing Authentication for Critical Function EPSS 0.6%CVE-2023-5716CRITICALASUS Armoury Crate - Arbitrary File WriteEPSS 0.6%CVE-2023-21979HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.6%