Falhas do tipo CWE-306

2.613 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-65311MEDIUMMissing authentication for logging-configuration endpointEPSS 0.5%CVE-2023-54342CRITICALEclipse Equinox OSGi 3.8-3.18 Console Remote Code ExecutionEPSS 0.5%CVE-2026-61203CRITICALVulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is EPSS 0.5%CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%CVE-2024-40405HIGHIncorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker viaEPSS 0.5%CVE-2023-34392HIGHMissing Authentication for Critical FunctionEPSS 0.5%CVE-2019-25236HIGHiSeeQ Hybrid DVR WH-H4 1.03R Unauthenticated Live Stream DisclosureEPSS 0.5%CVE-2026-15576MEDIUMAgent receiver accepts mTLS requests without a client certificateEPSS 0.5%CVE-2026-55534HIGHPraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executionEPSS 0.5%CVE-2026-89263MEDIUMMoguBlog through 6.2 Missing Authentication on the Comment Email-Notification EndpointEPSS 0.5%CVE-2025-3090HIGHMB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24EPSS 0.5%CVE-2023-24527MEDIUMImproper Access Control in SAP NetWeaver AS Java for Deploy ServiceEPSS 0.5%CVE-2023-0116HIGHThe reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect avaiEPSS 0.5%CVE-2026-53868HIGHCapgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and DeletionEPSS 0.5%CVE-2025-61777CRITICALFlagForge Allows Unauthenticated Badge Template API AccessEPSS 0.5%CVE-2026-70559HIGHDinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAllEPSS 0.5%CVE-2021-36780HIGHUnauthorized data access from replicas through vulnerable instance manager podsEPSS 0.5%CVE-2023-5253MEDIUMCheck Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0EPSS 0.5%CVE-2026-42864CRITICALFireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theftEPSS 0.4%CVE-2026-20343HIGHCisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service VulnerabilityEPSS 0.4%