Fallos del tipo CWE-306

2630 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-40856HIGHConfig disclosure in T-Mobile 5G Box IDU routersEPSS 0.4%CVE-2026-49471HIGHSerena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEEPSS 0.4%CVE-2025-3319HIGHIBM Spectrum Protect Server authentication bypassEPSS 0.4%CVE-2026-54365HIGHCentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dllEPSS 0.4%CVE-2025-41689HIGHWiesemann & Theis: Motherbox 3 allows unauthenticated read-only DB accessEPSS 0.4%CVE-2026-58197HIGHToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movementEPSS 0.4%CVE-2026-61239CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supporEPSS 0.4%CVE-2025-59780HIGHGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.4%CVE-2026-71566CRITICALKubeVirt backend is not authenticatedEPSS 0.4%CVE-2026-8694MEDIUMImproper access control on the API documentation endpoint in PowerShell UniversalEPSS 0.4%CVE-2026-2675MEDIUMMissing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.EPSS 0.4%CVE-2025-14300HIGHUnauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425EPSS 0.4%CVE-2025-47850MEDIUMIn JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloningEPSS 0.4%CVE-2026-77977HIGHEbyte NA111-M Missing Authentication for Critical FunctionEPSS 0.4%CVE-2025-14294MEDIUMRazorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order ModificationEPSS 0.4%CVE-2024-40087CRITICALVilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 alEPSS 0.4%CVE-2026-81664MEDIUMOpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /system/telemetry RouteEPSS 0.4%CVE-2026-10711HIGHRCE in Akınsoft's CafePlusEPSS 0.4%CVE-2026-49195HIGHPredator Connect W6x: unauthenticated Debug ServiceEPSS 0.4%CVE-2026-7187HIGHImproper Authentication in Universal Sotware's UKBSEPSS 0.4%