Falhas do tipo CWE-306

2.618 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-60361CRITICALVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%CVE-2026-61168HIGHVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.EPSS 0.4%CVE-2025-27803MEDIUMMissing Authentication in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 0.4%CVE-2024-35143MEDIUMIBM Planning Analytics Local missing authenticationEPSS 0.4%CVE-2024-37303MEDIUMSynapse unauthenticated writes to the media repository allow planting of problematic contentEPSS 0.4%CVE-2026-42176MEDIUMScoold: Persistent Admin Takeover by Overwriting the admins Configuration Setting via Forged JWT (missing `jti` validation)EPSS 0.4%CVE-2026-32896MEDIUMOpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles PluginEPSS 0.4%CVE-2026-77644CRITICALCritical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise EditionEPSS 0.4%CVE-2025-34190HIGHVasion Print (formerly PrinterLogic) PrinterInstallerClientService Authentication Bypass via LD_PRELOAD HookingEPSS 0.4%CVE-2025-54851HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.4%CVE-2026-68070HIGHMissing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product LineupsEPSS 0.4%CVE-2026-5768HIGHFourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical FunctionEPSS 0.4%CVE-2025-49652CRITICALImproper access control allows arbitrary account creationEPSS 0.4%CVE-2025-27019CRITICALRemote shell service (RSH) in Infinera MTC-9EPSS 0.4%CVE-2026-30885MEDIUMWWBN AVideo - Unauthenticated IDOR - Playlist Information DisclosureEPSS 0.4%CVE-2026-60365CRITICALVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for EPSS 0.4%CVE-2026-87128CRITICALVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.4%CVE-2026-73952CRITICALVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that areEPSS 0.4%CVE-2026-46892CRITICALVulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The suEPSS 0.4%CVE-2026-16771HIGHCVE-2026-16771EPSS 0.4%