Falhas do tipo CWE-306

2.608 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-25071HIGHXikeStor SKS8310-8X switch_config.src Missing AuthenticationEPSS 0.5%CVE-2023-22101HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-58473CRITICALCognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settingsEPSS 0.5%CVE-2018-25136HIGHFLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2025-15620CRITICALHiOS Switch Platform Denial-of-Service via Web InterfaceEPSS 0.5%CVE-2024-54983CRITICALAn issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.EPSS 0.5%CVE-2026-26319HIGHOpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated RequestsEPSS 0.5%CVE-2024-54984CRITICALAn issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the EPSS 0.5%CVE-2026-88285CRITICALGV-LPC2011/LPC2211 - Unauthenticated PTZ Control ServiceEPSS 0.5%CVE-2025-27935HIGHAuthentication Bypass in OTP (One-time Passcode) IdP Adapter Integration KitEPSS 0.5%CVE-2024-45229MEDIUMThe Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, andEPSS 0.5%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.5%CVE-2020-7479—A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), EPSS 0.5%CVE-2026-88065HIGH`tts-be` application has a Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-53469CRITICALMigration-planner: unprotected delete endpoint wipes all tenant dataEPSS 0.5%CVE-2026-61233CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported EPSS 0.5%CVE-2026-60289CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60240CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60288CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60253CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%