Falhas do tipo CWE-306

2.613 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-79668MEDIUMEch0 before 4.7.3 Unauthenticated Like Endpoint Metric InflationEPSS 0.4%CVE-2026-45248MEDIUMHedera Guardian Authentication Bypass Information DisclosureEPSS 0.4%CVE-2024-30391MEDIUMJunos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performedEPSS 0.4%CVE-2026-33159MEDIUMCraft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted usersEPSS 0.4%CVE-2026-9142CRITICALInsecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not presentEPSS 0.4%CVE-2023-40585HIGHUnauthenticated access to Ironic APIEPSS 0.4%CVE-2016-15045HIGHDeepin lastore-daemon Privilege Escalation via Unsigned .deb InstallationEPSS 0.4%CVE-2026-60920HIGHVulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are EPSS 0.4%CVE-2026-46824CRITICALVulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). SEPSS 0.4%CVE-2026-46903HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). SuppoEPSS 0.4%CVE-2026-60627CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported versionEPSS 0.4%CVE-2026-60618HIGHVulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). EPSS 0.4%CVE-2026-46964CRITICALVulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). SEPSS 0.4%CVE-2026-60872HIGHVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2026-61146CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-62478HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.4%CVE-2026-46951HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.4%CVE-2026-62447HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affecteEPSS 0.4%CVE-2026-60398HIGHVulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.EPSS 0.4%CVE-2026-47004HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). SuppoEPSS 0.4%