Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-49357HIGHStreamable HTTP mode exposes LINE Desktop read/send tools without MCP authenticationEPSS 0.6%CVE-2026-79954HIGHNASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCIDEPSS 0.6%CVE-2025-46275CRITICALPlanet Technology Network Products Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-44329CRITICALfree5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlersEPSS 0.6%CVE-2024-45438CRITICALAn issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.phEPSS 0.6%CVE-2023-22087HIGHVulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported veEPSS 0.6%CVE-2026-6376HIGHMissing authentication for critical function in SpiceJet Online Booking SystemEPSS 0.6%CVE-2026-68953HIGHMissing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product LineupsEPSS 0.6%CVE-2026-92808CRITICALServer-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System CompromiseEPSS 0.6%CVE-2025-65824HIGHAn unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using BlEPSS 0.6%CVE-2022-50981CRITICALMultiple Innomic VibroLine VLX HD 5.0 and avibia AVLX weak password requirementsEPSS 0.6%CVE-2025-26366HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2025-26362HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2025-26365HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2025-26363HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2023-27256MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.6%CVE-2025-26364HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11EPSS 0.6%CVE-2026-27584CRITICALActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpointsEPSS 0.6%CVE-2019-25632MEDIUMphpFileManager 1.7.8 Local File Inclusion via index.phpEPSS 0.6%CVE-2025-29870HIGHMissing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticaEPSS 0.6%