Falhas do tipo CWE-306

2.613 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-43798HIGHChisel AUTH environment variable not respected in server entrypointEPSS 0.4%CVE-2026-100672HIGHgrav-plugin-comments before 1.2.11 Unauthenticated Information DisclosureEPSS 0.4%CVE-2024-48775HIGHAn issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update procEPSS 0.4%CVE-2024-48777HIGHLEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.EPSS 0.4%CVE-2024-48776HIGHAn issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update processEPSS 0.4%CVE-2026-34411MEDIUMAppsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIsEPSS 0.4%CVE-2026-63098MEDIUMTheHive 4.1.24 Unauthenticated Information Disclosure via /api/status EndpointEPSS 0.4%CVE-2026-82265MEDIUMZipkin Unauthenticated Spring Boot Actuator Endpoints ExposureEPSS 0.4%CVE-2024-48773HIGHAn issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update processEPSS 0.4%CVE-2025-11949HIGHDigiwin|EasyFlow .NET and EasyFlow AiNet - Missing AuthenticationEPSS 0.4%CVE-2026-24068HIGHMissing XPC Client & NSXPC endpoint validation leads to privilege escalation in Vienna Assistant (MacOS) - Vienna Symphonic LibraryEPSS 0.4%CVE-2026-55538HIGHPraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticatedEPSS 0.4%CVE-2026-41039HIGHInformation Disclosure Vulnerability in Quantum Networks Router QN-I-470EPSS 0.4%CVE-2023-45851HIGHThe Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  EPSS 0.4%CVE-2026-70979CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-23767CRITICALESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization,EPSS 0.4%CVE-2026-33543CRITICALFOSSBilling: Authentication bypass allows unauthenticated administrator creationEPSS 0.4%CVE-2026-70977CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-60591CRITICALVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2026-87223CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%