Falhas do tipo CWE-306

2.605 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-58375HIGHJimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/exportEPSS 0.6%CVE-2026-35064HIGHSenseLive X3050 Missing authentication for critical functionEPSS 0.6%CVE-2026-72586HIGHfrangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event HandlerEPSS 0.6%CVE-2026-92720CRITICALKubero through 3.1.1 Unauthenticated Notifications API AccessEPSS 0.6%CVE-2026-85701MEDIUMramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authenticationEPSS 0.6%CVE-2026-28472CRITICALOpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect HandshakeEPSS 0.6%CVE-2022-50595CRITICALAdvantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCEEPSS 0.6%CVE-2026-14162CRITICALAdvantech|Hospital Quering Management - Missing AuthenticationEPSS 0.6%CVE-2026-71262CRITICALIoTSharp BlobStorageController Missing Authentication and Path TraversalEPSS 0.6%CVE-2022-50592CRITICALAdvantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCEEPSS 0.6%CVE-2023-28470MEDIUMIn Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.EPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%CVE-2025-58083CRITICALGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-75479HIGHJimuReport Unauthenticated Report Listing and Share Token DisclosureEPSS 0.6%CVE-2026-71319CRITICALNuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionEPSS 0.6%CVE-2021-4469HIGHDenver SHO-110 IP Camera Unauthenticated Snapshot AccessEPSS 0.6%CVE-2026-19749MEDIUMTenda CH7 RTSP/ONVIF missing authenticationEPSS 0.6%CVE-2022-41629HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, whichEPSS 0.6%CVE-2025-53938MEDIUMWeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpointsEPSS 0.6%CVE-2021-32709MEDIUMCreation of order credits was not validated by acl in admin ordersEPSS 0.6%