Fallos del tipo CWE-306

2630 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-49195HIGHPredator Connect W6x: unauthenticated Debug ServiceEPSS 0.4%CVE-2024-40087CRITICALVilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 alEPSS 0.4%CVE-2025-11671MEDIUMEBM Technologies|Uniweb/SoliPACS WebServer - Missing AuthenticationEPSS 0.4%CVE-2025-11672MEDIUMEBM Technologies|Uniweb/SoliPACS WebServer - Missing AuthenticationEPSS 0.4%CVE-2026-68578HIGHArcadeDB before 26.7.3 Authentication Bypass via MCP TransportEPSS 0.4%CVE-2025-8754HIGHABB AbilityTM zenon Remote Transport VulnerabilityEPSS 0.4%CVE-2026-83334HIGHVulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versionsEPSS 0.4%CVE-2025-63435MEDIUMXtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible foEPSS 0.4%CVE-2026-59715LOWOpen WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)EPSS 0.4%CVE-2026-47019HIGHVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected EPSS 0.4%CVE-2026-70805HIGHVulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versiEPSS 0.4%CVE-2026-57495HIGHAgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)EPSS 0.4%CVE-2026-60653HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2024-43272MEDIUMWordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Unpublished Campaign Viewer vulnerabilityEPSS 0.4%CVE-2026-19441MEDIUMUnauthenticated API Allows Analytics Data Manipulation in IKAS Technology's RushEPSS 0.4%CVE-2024-7079MEDIUMOpenshift-console: unauthenticated installation of helm chartsEPSS 0.4%CVE-2026-5267HIGHUnauthenticated Event Stream Exposure of Session Tokens in Navigator NCSEPSS 0.4%CVE-2024-9430MEDIUMGet Quote For Woocommerce – Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV DownloadEPSS 0.4%CVE-2023-30612MEDIUMMalicious HTTP requests could close arbitrary opening file descriptors in cloud-hypervisorEPSS 0.4%CVE-2018-25241HIGHVPN Browser+ 1.1.0.0 Denial of ServiceEPSS 0.4%