Fallos del tipo CWE-306

2630 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-75601MEDIUMStatic Web Server: Authentication bypass on /metrics endpoint when --basic-auth is enabledEPSS 0.4%CVE-2026-61106HIGHVulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. DifficultEPSS 0.4%CVE-2026-35279HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versionsEPSS 0.4%CVE-2026-60621HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version EPSS 0.4%CVE-2026-60742HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions thEPSS 0.4%CVE-2026-60169HIGHVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2026-71068HIGHVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.4%CVE-2026-4582LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authenticationEPSS 0.4%CVE-2026-60670HIGHVulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). SupportedEPSS 0.4%CVE-2026-62547HIGHVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.4%CVE-2026-60831HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions thaEPSS 0.4%CVE-2026-60979HIGHVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2026-60201HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-60424CRITICALVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%CVE-2026-46920HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.4%CVE-2024-21146HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affecEPSS 0.4%CVE-2024-42456HIGHA vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates crEPSS 0.4%CVE-2025-30762HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-2491MEDIUMSocomec DIRIS A-40 HTTP API Authentication Bypass VulnerabilityEPSS 0.4%CVE-2023-45140MEDIUMGroup-based JIT MFA bypass on scp and sftp in The BastionEPSS 0.4%