Falhas do tipo CWE-306

2.611 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-61594CRITICALdjust has an authorization bypass on the WebSocket/SSE mount pathEPSS 0.5%CVE-2022-23862HIGHA Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMEPSS 0.5%CVE-2026-71241HIGHBook-Management-System - Unauthenticated Disclosure of Student PII and Borrowing HistoryEPSS 0.5%CVE-2025-65112CRITICALPubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity SpoofingEPSS 0.5%CVE-2026-69228MEDIUMmissing authentication vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2023-0919HIGHMissing Authentication for Critical Function in kareadita/kavitaEPSS 0.5%CVE-2026-80462CRITICALPrivilege Escalation in Progress Chef AutomateEPSS 0.5%CVE-2026-8364CRITICALGladinet Triofox Missing Authentication for Critical FunctionsEPSS 0.5%CVE-2026-25192CRITICALCTEK Chargeportal Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%CVE-2026-82994CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83261CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is afEPSS 0.5%CVE-2026-70756CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-83000CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83021CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affEPSS 0.5%CVE-2026-83151CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83020CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83462CRITICALVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.5%CVE-2026-83232CRITICALVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versiEPSS 0.5%CVE-2026-73961CRITICALVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.5%