Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-63206CRITICALAn authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing atEPSS 0.5%CVE-2024-0949CRITICALImproper Access Control in Talya Informatics' ElektrawebEPSS 0.5%CVE-2023-54350HIGHWordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedEPSS 0.5%CVE-2025-34230MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via HP log_off_single_sign_on.phpEPSS 0.5%CVE-2018-25139HIGHFLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2025-34229MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via HP installApp.phpEPSS 0.5%CVE-2023-4857HIGH An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI caEPSS 0.5%CVE-2023-53773HIGHMiniDVBLinux 5.4 Unauthenticated Live Stream Disclosure via tv_action.shEPSS 0.5%CVE-2019-25226HIGHDongyoung Media DM-AP240T/W Unauthenticated Configuration DisclosureEPSS 0.5%CVE-2026-44327CRITICALfree5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerEPSS 0.5%CVE-2026-86727HIGHAVideo through 29.0 Information Disclosure via stats.json.phpEPSS 0.5%CVE-2025-34331HIGHAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Read via download.phpEPSS 0.5%CVE-2025-40771CRITICALA vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6EPSS 0.5%CVE-2026-20781CRITICALCloudCharge cloudcharge.se Missing Authentication for Critical FunctionEPSS 0.5%CVE-2022-4240MEDIUMUnauthenticated API allowing an attacker to obtain the information about network resourcesEPSS 0.5%CVE-2023-53974HIGHD-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated RequestEPSS 0.5%CVE-2026-1023HIGHGotac|Statistics Database System - Missing AuthenticationEPSS 0.5%CVE-2023-27261MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2023-26579MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2026-14529CRITICALIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgeryEPSS 0.5%