Falhas do tipo CWE-306

2.610 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2022-50591HIGHAdvantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2026-63647CRITICALCordysCRM SSE Notification Stream Hijack via `/sse/subscribe`EPSS 0.5%CVE-2026-55884CRITICALTilt: Missing authentication on the network-exposed Tilt HUD serverEPSS 0.5%CVE-2023-34761—An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypassEPSS 0.5%CVE-2026-34758CRITICALOneUptime: Missing Authentication on Notification EndpointsEPSS 0.5%CVE-2026-28450HIGHOpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP EndpointsEPSS 0.5%CVE-2026-25791HIGHSliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of ServiceEPSS 0.5%CVE-2026-92717CRITICALCovenant through 0.6 Missing Authentication on the CovenantHub SignalR HubEPSS 0.5%CVE-2026-61155CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2026-46910CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). SupportedEPSS 0.5%CVE-2026-61130CRITICALVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.5%CVE-2026-33719HIGHAVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.phpEPSS 0.5%CVE-2022-0878MEDIUMNovel attack against the Combined Charging System (CCS) in electric vehicles to remotely cause a denial of serviceEPSS 0.5%CVE-2026-47040CRITICALVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.EPSS 0.5%CVE-2026-25878MEDIUMFroshAdminer Adminer UI is accessible without admin sessionEPSS 0.5%CVE-2026-1632CRITICALRISS SRL MOMA Seismic Station Missing Authentication for Critical FunctionEPSS 0.5%CVE-2025-41715CRITICALMissing Authentication for Database Access in Web ApplicationEPSS 0.5%CVE-2024-22415HIGHUnsecured endpoints in the jupyter-lsp server extensionEPSS 0.5%CVE-2024-4428MEDIUMSensetive Data Exposure in Menulux Managment PortalEPSS 0.5%CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%