Falhas do tipo CWE-306

2.613 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-1332MEDIUMHAMASTAR Technology|MeetingHub - Missing AuthenticationEPSS 0.5%CVE-2024-11980HIGHBillion Electric router - Missing AuthenticationEPSS 0.5%CVE-2025-52024CRITICALA vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthentEPSS 0.5%CVE-2025-7679CRITICALSession ID Basic Auth BypassEPSS 0.5%CVE-2024-48920CRITICALPutongOJ: unprivileged users can escalate privileges by constructing requestsEPSS 0.5%CVE-2026-30866HIGHCombodo iTop: Insecured access to uploaded images via sniffed urlEPSS 0.5%CVE-2026-1724MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.5%CVE-2026-12562HIGHToptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-54598HIGHMissing Authentication for Critical Function in wallosEPSS 0.5%CVE-2024-40404CRITICALCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web SockeEPSS 0.5%CVE-2026-24790HIGHWelker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller Missing Authentication for Critical FunctionEPSS 0.5%CVE-2022-50594HIGHAdvantech iView < v5.7.04 Build 6425 data Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2026-73710HIGHUnauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric ComposerEPSS 0.5%CVE-2024-10774HIGHSICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIsEPSS 0.5%CVE-2025-25265MEDIUMUnauthenticated File Read via Web InterfaceEPSS 0.5%CVE-2026-73706HIGHAuthentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized ChangesEPSS 0.5%CVE-2026-18673MEDIUMKong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authenticationEPSS 0.5%CVE-2019-25240HIGHRifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticated Live Stream Disclosure via animate.cgiEPSS 0.5%CVE-2025-7405HIGHInformation Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU moduleEPSS 0.5%CVE-2026-56321MEDIUMCapgo - Missing Authentication Middleware on GET /private/role_bindings EndpointEPSS 0.5%