Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-9994CRITICALAmp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not require authenticationEPSS 0.5%CVE-2026-14446CRITICALIBM WebSphere Application Server is affected by a privilege escalationEPSS 0.5%CVE-2026-1341CRITICALMissing Authentication for Critical Function in Avation Light Engine ProEPSS 0.5%CVE-2026-30933HIGHFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/infoEPSS 0.5%CVE-2024-39601HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1EPSS 0.5%CVE-2024-12757HIGHNedap Librix Ecoreader Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-23944HIGHArcane allows unauthenticated proxy access to remote environmentsEPSS 0.5%CVE-2026-48814CRITICALNetwork-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)EPSS 0.5%CVE-2020-22661MEDIUMIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.5%CVE-2026-40289CRITICALPraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessionsEPSS 0.5%CVE-2026-33038HIGHAVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deploymentsEPSS 0.5%CVE-2026-63101HIGHOpen Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export EndpointEPSS 0.5%CVE-2026-3323HIGHVEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devicesEPSS 0.5%CVE-2026-75133HIGHKeep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_processEPSS 0.5%CVE-2026-88259HIGHCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-23783HIGHImproper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows aEPSS 0.5%CVE-2025-8861CRITICALChanging|TSA - Missing AuthenticationEPSS 0.5%CVE-2025-34222CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Admin APIs Used to Modify SSL CertificatesEPSS 0.5%CVE-2021-47731CRITICALSelea Targa IP Camera Developer Backdoor Configuration OverwriteEPSS 0.5%CVE-2024-48768HIGHAn issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmwaEPSS 0.5%