Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2021-32930The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and eEPSS 8.1%CVE-2025-52089HIGHA hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to exEPSS 8.0%CVE-2024-21006HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 7.9%CVE-2025-59246CRITICALAzure Entra ID Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2023-7308HIGHSecGate3600 Firewall Information Disclosure via authManageSet.cgiEPSS 7.5%CVE-2015-10141CRITICALXdebug Remote Debugger Unauthenticated OS Command ExecutionEPSS 7.4%CVE-2023-37265CRITICALIncorrect identification of source IP addresses in CasaOSEPSS 7.4%CVE-2025-24865CRITICALmySCADA myPRO Manager Missing Authentication for Critical FunctionEPSS 7.2%CVE-2025-55583CRITICALD-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi EPSS 7.0%CVE-2024-32735CRITICALCyberPower PowerPanel Enterprise Missing AuthenticationEPSS 6.8%CVE-2026-62241CRITICALclawvet < 0.7.5 Hard-coded JWT Secret Session ForgeryEPSS 6.5%CVE-2025-52692HIGHBypass AuthenticationEPSS 6.4%CVE-2022-46463HIGHAn access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. EPSS 6.2%CVE-2024-57725MEDIUMAn issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication,EPSS 6.2%CVE-2025-34103CRITICALWePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgiEPSS 6.0%CVE-2024-5721HIGHLogsign Unified SecOps Platform Missing Authentication Remote Code Execution VulnerabilityEPSS 6.0%CVE-2017-3184ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory EPSS 5.9%CVE-2024-21306MEDIUMMicrosoft Bluetooth Driver Spoofing VulnerabilityEPSS 5.8%CVE-2023-54335CRITICALeXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)EPSS 5.8%CVE-2025-14346CRITICALWHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within ranEPSS 5.6%