Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-34232MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via Lexmark dellCheck.phpEPSS 0.6%CVE-2022-43761CRITICALLack of authentication when managing APROL databaseEPSS 0.6%CVE-2026-78480HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.6%CVE-2025-40664CRITICALMissing authentication vulnerability in TCMAN GIM v11EPSS 0.5%CVE-2026-14525CRITICALIBM WebSphere Application Server Liberty is affected by an authenication bypassEPSS 0.5%CVE-2023-54344CRITICALEclipse Equinox OSGi 3.7.2 Remote Code Execution via ConsoleEPSS 0.5%CVE-2026-33366MEDIUMMissing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the proEPSS 0.5%CVE-2024-42462CRITICALBypass multifactor authenticationEPSS 0.5%CVE-2023-3104MEDIUMMissing Authentication for Critical Function in Unitree Robotics A1EPSS 0.5%CVE-2026-4436HIGHGPL Odorizers GPL750 Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-75919MEDIUMphpMyFAQ before 4.1.7 Authentication Bypass via Setup APIEPSS 0.5%CVE-2026-60372CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2024-8530MEDIUMCWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generatEPSS 0.5%CVE-2023-1837HIGHMissing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affEPSS 0.5%CVE-2026-60366CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-24934MEDIUMMicrosoft Defender Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-42017CRITICALAn issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenarEPSS 0.5%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.5%CVE-2026-1453CRITICALMissing Authentication for Critical Function in KiloView Encoder SeriesEPSS 0.5%