Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2019-25227HIGHTellion HN-2204AP Unauthenticated Configuration DisclosureEPSS 0.5%CVE-2025-45814CRITICALMissing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attacEPSS 0.5%CVE-2025-11529MEDIUMChurchCRM API Endpoint AuthMiddleware.php AuthMiddleware missing authenticationEPSS 0.5%CVE-2025-30727CRITICALVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected EPSS 0.5%CVE-2026-31240HIGHThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as upEPSS 0.5%CVE-2023-37373MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file writeEPSS 0.5%CVE-2024-48882HIGHA denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pEPSS 0.5%CVE-2026-33951MEDIUMsignalk-server: Unauthenticated Source Priorities ManipulationEPSS 0.5%CVE-2025-23417HIGHA denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted EPSS 0.5%CVE-2024-56799CRITICALSimofa Allows Unauthenticated Access to API RoutesEPSS 0.5%CVE-2025-62582CRITICALDIAView - Authentication Bypass VulnerabilityEPSS 0.5%CVE-2025-7328CRITICALRockwell Automation Comms - 1783-NATR Multiple Broken Authentication VulnerabilitiesEPSS 0.5%CVE-2024-12869MEDIUMImproper Authentication in infiniflow/ragflowEPSS 0.5%CVE-2026-56286HIGHCapgo - Account Deletion Without Password ConfirmationEPSS 0.5%CVE-2026-44328HIGHfree5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutatingEPSS 0.5%CVE-2024-50381HIGHMissing Authentication for Critical Function in Snap One OVRC cloudEPSS 0.5%CVE-2026-14952HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authenticationEPSS 0.5%CVE-2026-41899MEDIUMCoolify unauthenticated feedback endpoint allows Discord webhook abuseEPSS 0.5%CVE-2025-0355HIGHMissing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and EPSS 0.5%CVE-2026-67578HIGHFA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the EPSS 0.5%