Falhas do tipo CWE-306

2.619 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2026-61158HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-60689HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.4%CVE-2026-60704HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.4%CVE-2024-58300HIGHSiklu MultiHaul TG Series < 2.0.0 Unauthenticated Credential Disclosure VulnerabilityEPSS 0.4%CVE-2026-65114HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical funcEPSS 0.4%CVE-2023-39380—Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnorEPSS 0.4%CVE-2026-59506CRITICALPriority – CWE-306: Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-4370CRITICALImproper TLS Client/Server authentication and certificate verification on Database ClusterEPSS 0.4%CVE-2026-56725HIGHZammad: Denial of Service via OTRS Import ControllerEPSS 0.4%CVE-2026-6736MEDIUMAuthentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity providerEPSS 0.4%CVE-2026-2756LOWOmniPEMF NeoRhythm BLE missing authenticationEPSS 0.4%CVE-2023-31132HIGHCacti Privilege EscalationEPSS 0.4%CVE-2026-10281MEDIUMEnderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authenticationEPSS 0.4%CVE-2024-1662HIGHInformation Disclosure in Porty's PowerBankEPSS 0.4%CVE-2025-10267MEDIUMNewType Infortech|NUP Portal - Missing AuthenticationEPSS 0.4%CVE-2025-7774HIGHRockwell Automation ArmorBlock 5000 I/O – Web Server VulnerabilitiesEPSS 0.4%CVE-2024-36555CRITICALBuilt-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch EPSS 0.4%CVE-2024-8057MEDIUMImproper Access Control in danswer-ai/danswerEPSS 0.4%CVE-2024-8074CRITICALSensetive Data Exposure in Nomysoft Informatics' NomysemEPSS 0.4%CVE-2026-79645HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%