Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-16015MEDIUMpoco-ai poco-claw executor_manager API tasks.py create_task missing authenticationEPSS 0.6%CVE-2021-32700CRITICALSupply chain attack via MiTM against usersEPSS 0.6%CVE-2024-8456CRITICALPLANET Technology switch devices - Missing Authentication for multiple HTTP routesEPSS 0.6%CVE-2026-1364CRITICALJNC|IAQS and I6 - Missing AuthenticationEPSS 0.6%CVE-2024-7940HIGHThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.6%CVE-2025-32440CRITICALNetAlertX Vulnerable to Authentication BypassEPSS 0.6%CVE-2026-24731CRITICALEV2GO ev2go.io Missing Authentication for Critical FunctionEPSS 0.6%CVE-2023-24526MEDIUMImproper Access Control in SAP NetWeaver AS Java (Classload Service)EPSS 0.6%CVE-2026-93960MEDIUMPixelfed OAuth Scope ApiV1Controller.php instancePeers missing authenticationEPSS 0.6%CVE-2025-25224MEDIUMThe LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerabilityEPSS 0.6%CVE-2026-3356CRITICALMissing Authentication for Critical Function vulnerability in Anritsu Remote Spectrum MonitorEPSS 0.6%CVE-2023-40393HIGHAn authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Photos iEPSS 0.6%CVE-2023-35872MEDIUMMissing Authentication check in SAP NetWeaver Process Integration (Message Display Tool)EPSS 0.6%CVE-2026-33203HIGHSiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive BypassEPSS 0.6%CVE-2023-35873MEDIUMMissing Authentication check in SAP NetWeaver Process Integration (Runtime Workbench)EPSS 0.6%CVE-2026-48911HIGHApache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation FlowEPSS 0.6%CVE-2025-4555CRITICALZONG YU Okcat Parking Management Platform - Missing AuthenticationEPSS 0.6%CVE-2026-82906MEDIUMsdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authenticationEPSS 0.6%CVE-2023-44152MEDIUMSensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber ProtectEPSS 0.6%CVE-2026-34160HIGHChamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata servicesEPSS 0.6%