Fallos del tipo CWE-306

2630 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-49399HIGHMissing Authentication for Critical Function in Elvaco M-Bus Metering Gateway CMe3100EPSS 0.4%CVE-2023-45140MEDIUMGroup-based JIT MFA bypass on scp and sftp in The BastionEPSS 0.4%CVE-2026-15563HIGHWildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dosEPSS 0.4%CVE-2025-59345HIGHDragonfly did not enable authentication for some Manager’s endpointsEPSS 0.4%CVE-2026-0204HIGHA vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific EPSS 0.4%CVE-2025-41716MEDIUMUnauthenticated User Enumeration via Missing AuthenticationEPSS 0.4%CVE-2024-6406HIGHSensetive Data Exposure in Yordam Information Technology's Mobile Library ApplicationEPSS 0.4%CVE-2026-35514MEDIUMUnauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions in ChartbrewEPSS 0.4%CVE-2024-41791MEDIUMA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not autheEPSS 0.4%CVE-2026-97231MEDIUMvolotat Anagnorisis Socket.IO Connect app.py missing authenticationEPSS 0.4%CVE-2026-54036MEDIUMLibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP VerificationEPSS 0.4%CVE-2025-43983CRITICALKuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_proceEPSS 0.4%CVE-2026-25751CRITICALFUXA Unauthenticated Exposure of Plaintext Database CredentialsEPSS 0.4%CVE-2026-89027MEDIUMminiOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication DowngradeEPSS 0.4%CVE-2023-44116—Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may caEPSS 0.4%CVE-2025-54864MEDIUMHydra missing authentication when triggering evaluations through GitHub and Gitea pluginsEPSS 0.4%CVE-2024-0336CRITICALImproper Access Control in EMTA Grups PDKSEPSS 0.4%CVE-2024-40091MEDIUMVilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve lEPSS 0.4%CVE-2026-44320HIGHfree5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing pathEPSS 0.4%CVE-2026-0842MEDIUMFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authenticationEPSS 0.4%