Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-84075CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2021-47933CRITICALWordPress MStore API 2.0.6 Arbitrary File UploadEPSS 0.6%CVE-2024-6422CRITICALPepperl+Fuchs: OIT Products can be manipulated via unintended Telnet accessEPSS 0.6%CVE-2024-6981CRITICALOMNTEC Proteus Tank Monitoring Missing Authentication for Critical FunctionEPSS 0.6%CVE-2022-41271CRITICALAn unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PEPSS 0.6%CVE-2026-32064HIGHOpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC ObserverEPSS 0.6%CVE-2026-69703CRITICALAtlas-Livre Unauthenticated Access via Admin Controllers Missing ExitEPSS 0.6%CVE-2026-88263HIGHXikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration datEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.6%CVE-2026-34731HIGHAVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.phpEPSS 0.6%CVE-2026-92729HIGHSigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics EndpointsEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2026-54061CRITICALDgraph Alpha group stores can be replaced via unauthenticated external snapshot importEPSS 0.6%CVE-2022-20861CRITICALCisco Nexus Dashboard Unauthorized Access VulnerabilitiesEPSS 0.6%CVE-2026-25848CRITICALIn JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possibleEPSS 0.6%CVE-2023-6221HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-8602HIGHMissing authentication for critical function in ScadaBREPSS 0.6%CVE-2020-5589—SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SPEPSS 0.6%CVE-2026-84700HIGHPika Unauthenticated Replication Access via Internal Protobuf PortEPSS 0.6%