Fallos del tipo CWE-306

2632 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2018-25241HIGHVPN Browser+ 1.1.0.0 Denial of ServiceEPSS 0.4%CVE-2026-81032CRITICALNebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime ConfigurationEPSS 0.4%CVE-2026-49217HIGHMailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictionsEPSS 0.4%CVE-2026-83305HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%CVE-2025-6792MEDIUMOne to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message InterceptionEPSS 0.4%CVE-2025-11986MEDIUMCrypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication StateEPSS 0.4%CVE-2024-3774MEDIUMaEnrich Technology a+HRD - Exposure of Sensitive DataEPSS 0.4%CVE-2018-25246HIGHWikipedia 12.0 Denial of Service via SearchEPSS 0.4%CVE-2025-53789HIGHWindows StateRepository API Server file Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-61590HIGHdjust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUGEPSS 0.4%CVE-2026-28352MEDIUMIndico missing access check in event series management APIEPSS 0.4%CVE-2026-86106HIGHSecurity Advisory 0179EPSS 0.4%CVE-2024-13173MEDIUMHealth information leakage vulnerabilityEPSS 0.4%CVE-2024-13186MEDIUMMinigameCenter information leakage vulnerabilityEPSS 0.4%CVE-2026-47671MEDIUMNhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secretsEPSS 0.4%CVE-2024-13185MEDIUMMinigameCenter module information leakage vulnerabilityEPSS 0.4%CVE-2026-35274HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.4%CVE-2026-87197HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-60652HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2026-60810HIGHVulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). SupportedEPSS 0.4%