Falhas do tipo CWE-306

2.610 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%CVE-2024-48791HIGHAn issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware EPSS 0.5%CVE-2026-8446HIGHLangflow is affected by security vulnerabilities in Model Context Protocol featuresEPSS 0.5%CVE-2025-26360MEDIUMA CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to versioEPSS 0.5%CVE-2026-59160HIGHYeger: Unauthenticated Network-Exposed Turborepo Task Execution via /api/runEPSS 0.5%CVE-2025-2407CRITICALMissing Authentication & Authorization in Web-API allows adversary unrestricted accessEPSS 0.5%CVE-2026-60918HIGHVulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions thatEPSS 0.5%CVE-2026-46922HIGHVulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.5%CVE-2026-60925HIGHVulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.5%CVE-2026-55533HIGHPraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secretEPSS 0.5%CVE-2026-61094HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.5%CVE-2026-65105HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service wEPSS 0.5%CVE-2026-60153HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected EPSS 0.5%CVE-2026-61285HIGHVulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported veEPSS 0.5%CVE-2026-60396HIGHVulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23EPSS 0.5%CVE-2026-34279CRITICALVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported EPSS 0.5%CVE-2026-60883HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are afEPSS 0.5%CVE-2026-55528HIGHpraisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)EPSS 0.5%CVE-2026-60335HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.5%CVE-2026-7844MEDIUMchatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authenticationEPSS 0.5%