Falhas do tipo CWE-306

2.618 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2023-41255HIGHThe vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abuEPSS 0.4%CVE-2026-83461HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2026-45577MEDIUMNeotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypassEPSS 0.4%CVE-2026-83266HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that EPSS 0.4%CVE-2026-25885CRITICALPolarLearn allows Unauthenticated WebSocket access allows subscribing to and posting in arbitrary group chatsEPSS 0.4%CVE-2024-26263MEDIUMEBM Technologies RISWEB - Improper Access ControlEPSS 0.4%CVE-2026-5749HIGHInadequate access control vulnerability in FullstepEPSS 0.4%CVE-2026-77248HIGHMCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transportEPSS 0.4%CVE-2025-32738MEDIUMMissing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlieEPSS 0.4%CVE-2025-55221HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70EPSS 0.4%CVE-2026-58071HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal AdministEPSS 0.4%CVE-2025-55222HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70EPSS 0.4%CVE-2025-54848HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.4%CVE-2026-42331HIGHFOSSBilling missing authorization in guest Invoice API endpointsEPSS 0.4%CVE-2024-32764CRITICALmyQNAPcloud LinkEPSS 0.4%CVE-2026-29132MEDIUMESWmail-Verify BypassEPSS 0.4%CVE-2026-60580HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2026-74245MEDIUMQuay: unauthenticated exported logs download in quayEPSS 0.4%CVE-2026-59971CRITICALMySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)EPSS 0.4%CVE-2025-30111HIGHOn IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized usEPSS 0.4%