Fallos del tipo CWE-306

2134 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-3248CRITICALLangflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codeEPSS 100.0%KEVCVE-2017-10271HIGHVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are EPSS 100.0%KEVCVE-2022-1388CRITICALOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior EPSS 100.0%KEVCVE-2026-33017CRITICALLangflow has Unauthenticated Remote Code Execution via Public Flow Build EndpointEPSS 99.8%KEVCVE-2021-37415CRITICALZoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authenticatioEPSS 99.8%KEVCVE-2023-21839HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 99.8%KEVCVE-2020-13927CRITICALThe previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riEPSS 99.8%KEVCVE-2024-0012CRITICALPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)EPSS 99.7%KEVCVE-2025-32433CRITICALErlang/OTP SSH Vulnerable to Pre-Authentication RCEEPSS 98.6%KEVCVE-2025-0108HIGHPAN-OS: Authentication Bypass in the Management Web InterfaceEPSS 98.5%KEVCVE-2022-21587CRITICALVulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions tEPSS 98.3%KEVCVE-2020-6207CRITICALSAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication forEPSS 98.3%KEVCVE-2026-41940CRITICALWebPros cPanel and WHM Authentication Bypass via Login FlowEPSS 97.9%KEVCVE-2025-34028CRITICALCommvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path TraversalEPSS 97.7%KEVCVE-2019-9082HIGHThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\appEPSS 97.4%KEVCVE-2026-20253CRITICALUnauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk EnterpriseEPSS 96.9%KEVCVE-2026-39987CRITICALmarimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassEPSS 96.6%KEVCVE-2021-35587CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affecEPSS 96.3%KEVCVE-2026-35273CRITICALVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported vEPSS 95.5%KEVCVE-2025-4008HIGHArbitrary Command Injection in Smartbedded MeteoBridgeEPSS 95.1%KEV