Falhas do tipo CWE-306

2.610 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2024-9137HIGHMoxa Service Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-3281HIGHA vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build EPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2023-25013HIGHAn issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in EPSS 0.5%CVE-2026-65310HIGHMissing authentication and permissive CORS policyEPSS 0.5%CVE-2026-76355HIGHUnauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk EnterpriseEPSS 0.5%CVE-2026-44100HIGHJupiCore charging point reconfiguration without authEPSS 0.5%CVE-2024-52438HIGHWordPress de:branding plugin <= 1.0.2 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-16527HIGHPcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rulesEPSS 0.5%CVE-2024-41969HIGHWAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesEPSS 0.5%CVE-2018-25137HIGHFLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated Config File DisclosureEPSS 0.5%CVE-2026-4649MEDIUMAuth bypass in Apache Artemis allows reading all internal messagesEPSS 0.5%CVE-2024-52437HIGHWordPress Banner System plugin <= 1.0.0 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-2567CRITICALLantronix Xport Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-86480CRITICALIn JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privilegesEPSS 0.5%CVE-2026-67349HIGHOpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin BypassEPSS 0.5%CVE-2026-91996HIGHlamp-cloud through 5.10.0 Missing Authentication for JVM Properties EndpointEPSS 0.5%CVE-2023-34761—An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypassEPSS 0.5%CVE-2026-63647CRITICALCordysCRM SSE Notification Stream Hijack via `/sse/subscribe`EPSS 0.5%