Falhas do tipo CWE-306

2.607 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-13510CRITICALIskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiyEPSS 0.6%CVE-2022-3738MEDIUMWAGO: Missing authentication for config export functionality in multiple productsEPSS 0.6%CVE-2023-22072CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected EPSS 0.6%CVE-2026-58574CRITICALDell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to thEPSS 0.6%CVE-2024-35293CRITICALSchneider Elektronik Series 700 prone to missing authentication for critical reset functionEPSS 0.6%CVE-2022-45433LOWSome Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall acEPSS 0.6%CVE-2023-30744HIGHImproper access control during application start-up in SAP AS NetWeaver JAVA.EPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2026-45327HIGHTinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injectionEPSS 0.6%CVE-2024-12511HIGHSMB/FTP Address Book Scan Pass-back attackEPSS 0.6%CVE-2026-50085HIGHAqara Board IoT insecure debug APIEPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%CVE-2026-82266CRITICALRedpanda Admin API Unauthenticated Superuser Access via Default ConfigurationEPSS 0.6%CVE-2026-34162CRITICALFastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key TheftEPSS 0.6%CVE-2026-54446HIGHNetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP ModeEPSS 0.6%CVE-2024-45049HIGHNix Hydra Missing authentication when triggering evaluationsEPSS 0.6%CVE-2026-20357CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.6%CVE-2026-56346MEDIUMAVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php EndpointEPSS 0.6%CVE-2026-69091HIGHAdmidio before 5.0.11 Authentication Bypass via forum.phpEPSS 0.6%CVE-2026-14976HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerabilityEPSS 0.6%