Falhas do tipo CWE-306

2.612 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2023-37495MEDIUMHCL Domino is susceptible to a weak cryptography vulnerabilityEPSS 0.5%CVE-2026-2234CRITICALHGiga|C&Cm@il - Missing AuthenticationEPSS 0.5%CVE-2026-60439HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2025-34434CRITICALAVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and DeletionEPSS 0.5%CVE-2026-61246HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-77097HIGHPrivate Metrics Server Denial of ServiceEPSS 0.5%CVE-2019-25686HIGHCore FTP 2.0 build 653 PBSZ Unauthenticated Denial of ServiceEPSS 0.5%CVE-2026-75479HIGHJimuReport Unauthenticated Report Listing and Share Token DisclosureEPSS 0.5%CVE-2024-8419HIGHImproper Access Control vulnerability in AC4xxS devicesEPSS 0.5%CVE-2025-32377MEDIUMRasa Pro Missing Authentication For Voice Connector APIsEPSS 0.5%CVE-2026-74243MEDIUMQuay: unauthenticated secscan notification endpoint in quay when psk is unsetEPSS 0.5%CVE-2026-86681HIGHBroken Access Control vulnerabilityEPSS 0.5%CVE-2026-83327CRITICALVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2026-70861HIGHVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supportEPSS 0.5%CVE-2023-33247HIGHTalend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be EPSS 0.5%CVE-2025-69285HIGHSQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerabilityEPSS 0.5%CVE-2026-1332MEDIUMHAMASTAR Technology|MeetingHub - Missing AuthenticationEPSS 0.5%CVE-2024-11980HIGHBillion Electric router - Missing AuthenticationEPSS 0.5%CVE-2022-43555HIGHIvanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2022-43554HIGHIvanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%