Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-34200HIGHNhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network PortEPSS 0.6%CVE-2026-73246HIGHKestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentialsEPSS 0.6%CVE-2026-51937HIGHAn issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.javEPSS 0.6%CVE-2026-82641HIGHKeploy 3.1.0-3.6.25 Unauthenticated TLS Key ExposureEPSS 0.6%CVE-2021-4461CRITICALSeeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication BypassEPSS 0.6%CVE-2026-67966CRITICALTenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shEPSS 0.6%CVE-2023-2187MEDIUMOn Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WeEPSS 0.6%CVE-2024-1573MEDIUMMissing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.EPSS 0.6%CVE-2023-49115HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-38059HIGHST Engineering iDirect iQ-Series Terminals Missing authentication for critical functionEPSS 0.6%CVE-2026-2165MEDIUMdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2023-22803HIGHCVE-2023-22803EPSS 0.6%CVE-2025-8558LOWInsider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated uEPSS 0.6%CVE-2024-32752HIGHJohnson Controls Software House iSTAR Configuration Utility (ICU) ToolEPSS 0.6%CVE-2024-41988CRITICALMissing Authentication for Critical Function vulnerability in TEM Opera Plus FM Family TransmitterEPSS 0.6%CVE-2026-65014MEDIUMn8n before 2.28.0 Authentication Bypass via test-webhookEPSS 0.6%CVE-2026-62325CRITICALgoshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)EPSS 0.6%CVE-2026-59808HIGHAVideo Authentication Bypass via Unkeyed Video Hash DisclosureEPSS 0.6%CVE-2026-84075CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%