Falhas do tipo CWE-306

2.592 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-34073CRITICALstamparm/maltrail <=0.54 Remote Command ExecutionEPSS 5.6%CVE-2026-3611CRITICALHoneywell IQ4x BMS Controller Missing authentication for critical functionEPSS 5.5%CVE-2026-67208CRITICALJuggle 1.6.0 Unauthenticated RCE via Exposed H2 ConsoleEPSS 5.3%CVE-2020-15798CRITICALA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP MoEPSS 5.2%CVE-2017-3216WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remoteEPSS 5.2%CVE-2018-10635In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code EPSS 5.1%CVE-2017-13997A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouchEPSS 5.1%CVE-2026-50507MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 5.0%CVE-2020-10920CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touchEPSS 4.9%CVE-2017-2637CRITICALA design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd isEPSS 4.8%CVE-2023-37483CRITICALImproper Access Control Vulnerabilities in SAP PowerDesignerEPSS 4.8%CVE-2022-36983HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not reqEPSS 4.7%CVE-2014-125118CRITICALeScan 5.5-2 Web Management Console Command InjectionEPSS 4.7%CVE-2026-58123CRITICALHermes WebUI < 0.51.788 Unauthenticated RCE via Terminal APIEPSS 4.6%CVE-2024-27890HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).EPSS 4.4%CVE-2025-34101CRITICALServiio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO ParameterEPSS 4.4%CVE-2026-0545HIGHMissing Authentication for Critical Function in mlflow/mlflowEPSS 4.4%CVE-2018-17924HIGHRockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could sEPSS 4.3%CVE-2022-25247CRITICALPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 4.1%CVE-2022-26501CRITICALVeeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).EPSS 4.1%KEV