Falhas do tipo CWE-306

2.613 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-65012MEDIUMInvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderEPSS 0.4%CVE-2024-7015HIGHImproper Authentication in Profelis Informatics and Consulting's PassBOXEPSS 0.4%CVE-2026-82282HIGHAtlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated CallersEPSS 0.4%CVE-2026-80208HIGHAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Account Closure EndpointsEPSS 0.4%CVE-2026-12722HIGHAuthentication Bypass in FTC Software's E-Commerce Management PanelEPSS 0.4%CVE-2026-22207CRITICALOpenViking Missing root_api_key Allows Anonymous ROOT AccessEPSS 0.4%CVE-2024-33622MEDIUMMissing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerabilitEPSS 0.4%CVE-2023-39436MEDIUMInformation Disclosure in SAP Supplier Relationship ManagementEPSS 0.4%CVE-2026-27471CRITICALERP: Document access through endpoints due to missing validationEPSS 0.4%CVE-2026-5029HIGHRCE in Code Runner MCP ServerEPSS 0.4%CVE-2023-27983MEDIUMA CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of rEPSS 0.4%CVE-2026-28458HIGHOpenClaw 2026.1.20 < 2026.2.1 - Missing Authentication in Browser Relay /cdp WebSocket EndpointEPSS 0.4%CVE-2026-50225HIGHAccount Creation ExhaustionEPSS 0.4%CVE-2026-57476MEDIUMDeloitte AI Assist for Customer unauthenticated RAG corpus read and writeEPSS 0.4%CVE-2026-34732MEDIUMAVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 EndpointsEPSS 0.4%CVE-2025-65731MEDIUMAn issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical acceEPSS 0.4%CVE-2026-0647HIGHRockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple VulnerabilitiesEPSS 0.4%CVE-2026-68929CRITICALFastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorizationEPSS 0.4%CVE-2026-61176MEDIUMVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2026-44775MEDIUMKavita: No authentication at /api/Reader/imageEPSS 0.4%