Falhas do tipo CWE-306

2.607 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-69091HIGHAdmidio before 5.0.11 Authentication Bypass via forum.phpEPSS 0.6%CVE-2026-84485HIGHAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search EndpointEPSS 0.6%CVE-2026-62422CRITICALIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass vEPSS 0.6%CVE-2026-50242CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via diEPSS 0.6%CVE-2026-72688HIGHOpenSignLabs opensignserver - Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-13007HIGHInsecure Public Caching on REST API Endpoints in Tenable Identity ExposureEPSS 0.6%CVE-2026-77254CRITICALMCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentialsEPSS 0.6%CVE-2026-81094CRITICALmcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring AuthenticationEPSS 0.6%CVE-2023-22650HIGHRancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderEPSS 0.6%CVE-2026-4767CRITICALImproper Access Control in TR7's WAF-ASPEPSS 0.6%CVE-2026-44321HIGHfree5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)EPSS 0.6%CVE-2022-35136MEDIUMBoodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.EPSS 0.6%CVE-2026-75329CRITICALThe Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can dirEPSS 0.6%CVE-2025-5906MEDIUMcode-projects Laundry System data missing authenticationEPSS 0.6%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.6%CVE-2023-5881HIGHUnauthenticated access permitted to web interface page "Garage Door Control Module Setup"EPSS 0.6%CVE-2026-28766CRITICALGardyn Cloud API Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-29613HIGHOpenClaw < 2026.2.12 - Webhook Authentication Bypass via Loopback remoteAddress TrustEPSS 0.6%CVE-2026-1729CRITICALAdForest <= 6.0.12 - Authentication BypassEPSS 0.6%CVE-2026-90543MEDIUMWWBN AVideo Missing Authentication via socketMessageLiveOwner.json.phpEPSS 0.6%