Falhas do tipo CWE-306

2.613 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2025-12108CRITICALMissing Authentication for Critical Function Survision License Plate Recognition CameraEPSS 0.4%CVE-2024-48771HIGHAn issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmwareEPSS 0.4%CVE-2024-45075HIGHIBM webMethods Integration privilege escalationEPSS 0.4%CVE-2026-45754MEDIUMSymfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event InjectionEPSS 0.4%CVE-2026-41273HIGHFlowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public ChatflowEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2026-60544HIGHVulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected areEPSS 0.4%CVE-2026-2844CRITICALTimePictra Authentication Bypass VulnerabilityEPSS 0.4%CVE-2025-0132MEDIUMCortex XDR Broker VM: Unauthenticated User Can Disable Internal ServicesEPSS 0.4%CVE-2026-61175CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2024-52285MEDIUMA vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < VEPSS 0.4%CVE-2026-15416HIGHArgo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpointEPSS 0.4%CVE-2026-59706CRITICALmem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_urlEPSS 0.4%CVE-2026-31983MEDIUMMissing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0EPSS 0.4%CVE-2024-21183HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-27509HIGHUnitree Go2 Missing DDS Authentication Enables Adjacent RCEEPSS 0.4%CVE-2024-48774HIGHAn issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware updatEPSS 0.4%CVE-2026-12183CRITICALNefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary CredentialsEPSS 0.4%CVE-2025-7115MEDIUMrowboatlabs rowboat Session route.ts PUT missing authenticationEPSS 0.4%CVE-2020-37146HIGHAptina AR0130 960P 1.3MP Camera - Remote Configuration DisclosureEPSS 0.4%