Falhas do tipo CWE-306

2.612 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-5872MEDIUMeGauge EG3000 Energy Monitor Setting missing authenticationEPSS 0.5%CVE-2026-32594MEDIUMParse Server GraphQL WebSocket endpoint bypasses security middlewareEPSS 0.5%CVE-2026-32957MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenEPSS 0.5%CVE-2026-84831HIGHMandatory MFA bypass before enrollmentEPSS 0.5%CVE-2025-5876MEDIUMLucky LM-520-SC/LM-520-FSC/LM-520-FSC-SAM missing authenticationEPSS 0.5%CVE-2025-41655HIGHPEPPERL+FUCHS: Attacker can cause a DoS via URLEPSS 0.5%CVE-2026-32962MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuEPSS 0.5%CVE-2026-84078CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-83197CRITICALVulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions thatEPSS 0.5%CVE-2019-25248HIGHBeward N100 M2.1.6 Unauthenticated RTSP Video Stream DisclosureEPSS 0.5%CVE-2022-50977HIGHMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via HTTPEPSS 0.5%CVE-2018-25141HIGHFLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2026-34227MEDIUMSliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP InterfaceEPSS 0.5%CVE-2026-79687CRITICALDell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access EPSS 0.5%CVE-2026-80132HIGHell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticatEPSS 0.5%CVE-2025-53037CRITICALVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.5%CVE-2026-92972HIGHSGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpointEPSS 0.5%CVE-2026-47769MEDIUMAPIFold Vulnerable to Unauthenticated Webhook Event InjectionEPSS 0.5%CVE-2024-21846MEDIUMElectrolink FM/DAB/TV Transmitter Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-2234CRITICALHGiga|C&Cm@il - Missing AuthenticationEPSS 0.5%