Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-19875HIGHUnauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in LangflowEPSS 0.5%CVE-2025-7114MEDIUMSimStudioAI sim Session route.ts POST missing authenticationEPSS 0.5%CVE-2025-70147HIGHMissing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackersEPSS 0.5%CVE-2026-19426HIGHFitSoft|POS Sytstem - Missing AuthenticationEPSS 0.5%CVE-2026-73669MEDIUMSignify Philips Hue Bridge Pro MQTT broker missing authenticationEPSS 0.5%CVE-2026-34952CRITICALPraisonAI: Missing Authentication in WebSocket GatewayEPSS 0.5%CVE-2023-21856HIGHVulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versEPSS 0.5%CVE-2025-4557HIGHZONG YU Parking Management System - Missing AuthenticationEPSS 0.5%CVE-2022-24396—The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be aEPSS 0.5%CVE-2026-12691HIGHAuthentication Bypass in Vimesoft's Enterprise Video PlatformEPSS 0.5%CVE-2018-25335CRITICALWordPress Plugin Peugeot Music 1.0 Arbitrary File UploadEPSS 0.5%CVE-2022-31701MEDIUMVMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this isEPSS 0.5%CVE-2025-3232HIGHMitsubishi Electric Europe smartRTU Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-21272HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0EPSS 0.5%CVE-2026-86801HIGHTo Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload HandlerEPSS 0.5%CVE-2023-53969CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password ChangeEPSS 0.5%CVE-2024-47902MEDIUMA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 0.5%CVE-2023-53967CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password ChangeEPSS 0.5%CVE-2025-5192CRITICALSoar Cloud HRD Human Resource Management System - Missing Authentication for Critical FunctionEPSS 0.5%CVE-2023-53970HIGHScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board ConfigEPSS 0.5%