Falhas do tipo CWE-306

2.619 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-55585CRITICALIn the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricEPSS 0.4%CVE-2026-40184LOWUnauthenticated Access to Uploaded Files in TREKEPSS 0.4%CVE-2025-40736CRITICALA vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorEPSS 0.4%CVE-2025-48742MEDIUMThe installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.EPSS 0.4%CVE-2026-45089HIGHDalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server ModeEPSS 0.4%CVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-18771HIGHMissing Authentication for Critical Function in TMT Machine's Talassoft Industrial Management SoftwareEPSS 0.4%CVE-2026-89176HIGHHowyar|WeenyGenius - Missing AuthenticationEPSS 0.4%CVE-2026-87200HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2025-32876MEDIUMAn issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure EPSS 0.4%CVE-2026-10617MEDIUMnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authenticationEPSS 0.4%CVE-2025-61752HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-35450MEDIUMWWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.phpEPSS 0.4%CVE-2026-86064HIGHKlever-Go: /log controls global node loggingEPSS 0.4%CVE-2025-27214CRITICALA Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical oEPSS 0.4%CVE-2026-79961MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%CVE-2024-31525HIGHPeppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges toEPSS 0.4%CVE-2022-0922MEDIUMICSMA-22-088-01 Philips e-AlertEPSS 0.4%CVE-2025-14577CRITICALPHP Function Injection in Slican NPC/IPL/IPM/IPUEPSS 0.4%CVE-2024-37767HIGHInsecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET reqEPSS 0.4%