Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-26082CRITICALA file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. EPSS 20.1%CVE-2024-10386CRITICALRockwell Automation FactoryTalk ThinManager Authentication VulnerabilityEPSS 19.3%CVE-2025-58443CRITICALFOG's authentication bypass leads to full SQL DB dumpEPSS 18.5%CVE-2019-5591MEDIUMA Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive informationEPSS 18.4%KEVCVE-2022-45504HIGHAn issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to EPSS 18.3%CVE-2025-61928CRITICALBetter Auth: Unauthenticated API key creation through api-key pluginEPSS 17.9%CVE-2010-5326CRITICALThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows rEPSS 17.8%KEVCVE-2019-6543AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20EPSS 17.3%CVE-2026-22812HIGHOpenCode's Unauthenticated HTTP Server Allows Arbitrary Command ExecutionEPSS 16.8%CVE-2026-59726CRITICALRuflo: Unauthenticated RCE in MCP bridge default docker-compose deploymentEPSS 16.4%CVE-2020-27986HIGHSonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE:EPSS 16.0%CVE-2021-28809CRITICALMissing Authentication for Critical Function in RTRR Server in HBS3EPSS 15.8%CVE-2024-42455HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserializatEPSS 15.2%CVE-2025-34077CRITICALWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCEEPSS 15.1%CVE-2023-27267CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge)EPSS 14.2%CVE-2025-41656CRITICALPilz: Missing Authentication in Node-RED integrationEPSS 13.8%CVE-2023-41183HIGHNETGEAR Orbi 760 SOAP API Authentication Bypass VulnerabilityEPSS 13.6%CVE-2020-12004The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and IgnitEPSS 13.6%CVE-2026-36356CRITICALThe GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injecEPSS 13.5%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEV