Falhas do tipo CWE-306

2.610 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2023-27259HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2026-60253CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60244CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-63429HIGHHeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextEPSS 0.5%CVE-2024-27758HIGHIn RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(cEPSS 0.5%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.5%CVE-2026-67426CRITICALFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationEPSS 0.5%CVE-2023-4884MEDIUMMultiple vulnerabilities in Open5GSEPSS 0.5%CVE-2026-65319HIGHFeedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/textEPSS 0.5%CVE-2026-55571HIGHdjust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler callsEPSS 0.5%CVE-2026-27449HIGHUmbraco.Engage.Forms Allows Unauthorized Access to Multiple API EndpointsEPSS 0.5%CVE-2022-32503HIGHAn issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect toEPSS 0.5%CVE-2026-15978HIGHCVE-2026-15978EPSS 0.5%CVE-2026-89250HIGHWWBN AVideo Unauthenticated File Read via getRecordedFile.phpEPSS 0.5%CVE-2025-25060HIGHMissing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server whEPSS 0.5%CVE-2026-80234MEDIUMCAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing AuthenticationEPSS 0.5%CVE-2024-10776HIGHSICK InspectorP61x and SICK InspectorP62x: missing authenticationEPSS 0.5%CVE-2026-9202CRITICALUnauthenticated User Registration Could Lead to Remote Code ExecutionEPSS 0.5%CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2023-51062MEDIUMAn unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers toEPSS 0.5%