Fallos del tipo CWE-306

2629 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-86064HIGHKlever-Go: /log controls global node loggingEPSS 0.4%CVE-2022-0922MEDIUMICSMA-22-088-01 Philips e-AlertEPSS 0.4%CVE-2021-47940CRITICALWordPress Download From Files 1.48 Arbitrary File UploadEPSS 0.4%CVE-2025-14577CRITICALPHP Function Injection in Slican NPC/IPL/IPM/IPUEPSS 0.4%CVE-2025-7045MEDIUMCloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config ActionEPSS 0.4%CVE-2024-37767HIGHInsecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET reqEPSS 0.4%CVE-2017-20220HIGHServiio PRO 1.8 Unauthenticated Password Change via REST APIEPSS 0.4%CVE-2026-3558HIGHPhilips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-44949HIGHUnauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhookEPSS 0.4%CVE-2025-12348MEDIUMEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task ExecutionEPSS 0.4%CVE-2025-61673HIGHKarapace is vulnerable to Authentication BypassEPSS 0.4%CVE-2026-76701MEDIUMUnauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2022-41505MEDIUMAn access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UAREPSS 0.4%CVE-2024-22326MEDIUMIBM System Storage improper authenticationEPSS 0.4%CVE-2026-83115HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versiEPSS 0.4%CVE-2025-20210HIGHCisco Catalyst Center Unprotected API EndpointEPSS 0.4%CVE-2024-53623HIGHIncorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.EPSS 0.4%CVE-2024-58336HIGHAkuvox Smart Intercom S539 Unauthenticated Video Stream DisclosureEPSS 0.4%CVE-2026-31846HIGHUnauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+EPSS 0.4%CVE-2023-45220HIGHThe Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol tEPSS 0.4%