Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-11661MEDIUMProjectsAndPrograms School Management System missing authenticationEPSS 0.5%CVE-2026-22096CRITICALMissing authentication for webserver endpointsEPSS 0.5%CVE-2026-44895CRITICALGitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab toolsEPSS 0.5%CVE-2025-8284CRITICALPacket Power EMX and EG Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-1453CRITICALMissing Authentication for Critical Function in KiloView Encoder SeriesEPSS 0.5%CVE-2026-54309HIGHn8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control SessionsEPSS 0.5%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.5%CVE-2022-41776HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration methoEPSS 0.5%CVE-2023-41367MEDIUMMissing Authentication check in SAP NetWeaver (Guided Procedures)EPSS 0.5%CVE-2026-50287HIGHMissing Authentication for Critical Function in @agenticmail/mcpEPSS 0.5%CVE-2026-12819CRITICALDVP-12SE Missing Authentication and Unauthorized Write access VulnerabilityEPSS 0.5%CVE-2026-42856HIGHNetwork-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool callsEPSS 0.5%CVE-2026-47136MEDIUMRustFS: Unauthenticated RustFS console license endpoint exposes license metadataEPSS 0.5%CVE-2026-90449MEDIUMWhen a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface EPSS 0.5%CVE-2026-45044HIGHRustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlersEPSS 0.5%CVE-2026-73673HIGHNetis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware AuthenticationEPSS 0.5%CVE-2025-63958CRITICALMILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.5%CVE-2026-9152CRITICALUnauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index DestructionEPSS 0.5%CVE-2024-41793HIGHA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an enEPSS 0.5%