Fallos del tipo CWE-306

2630 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-17057MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]EPSS 0.4%CVE-2026-13125HIGHGeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerabilityEPSS 0.4%CVE-2023-28761MEDIUMMissing Authentication check in SAP NetWeaver Enterprise PortalEPSS 0.4%CVE-2026-60255HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%CVE-2023-29061MEDIUMLack of Adequate BIOS AuthenticationEPSS 0.4%CVE-2026-82276MEDIUMStarRocks Frontend REST Handlers Bypass the Base Class Authentication GateEPSS 0.4%CVE-2023-7325CRITICALMingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRFEPSS 0.4%CVE-2026-86506MEDIUMIn JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling dataEPSS 0.4%CVE-2024-47912HIGHA vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an uEPSS 0.4%CVE-2026-54068MEDIUMSiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIconEPSS 0.4%CVE-2025-3474MEDIUMPanels - Critical - Access bypass - SA-CONTRIB-2025-033EPSS 0.4%CVE-2026-76447MEDIUMCisco Identity Services Engine Certificate Reload VulnerabilityEPSS 0.4%CVE-2026-0283MEDIUMPAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)EPSS 0.4%CVE-2026-50082MEDIUMAqara Developer Portal insecure authentication tokenEPSS 0.4%CVE-2026-48692HIGHFastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initializEPSS 0.4%CVE-2025-14349HIGHBusiness Logic Error in Universal Software's FlexCity/KioskEPSS 0.4%CVE-2026-56677HIGH9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test EndpointEPSS 0.4%CVE-2026-34949MEDIUMCombodo iTop: Unauthenticated user can delete .readonly fileEPSS 0.4%CVE-2026-60557MEDIUMVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-49471HIGHSerena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEEPSS 0.4%