Fallos del tipo CWE-306

2632 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-17635CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2020-5326MEDIUMAffected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage ReEPSS 0.3%CVE-2026-50227MEDIUMMQTT WebSocket Command Execution Vulnerability in NitroSenseEPSS 0.3%CVE-2026-53714HIGHEnvoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceModeEPSS 0.3%CVE-2025-12477CRITICALServer Version DisclosureEPSS 0.3%CVE-2025-52182HIGHThe Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.EPSS 0.3%CVE-2025-52551CRITICALProprietary protocol allows for unauthenticated file operationsEPSS 0.3%CVE-2019-25738CRITICALWordPress Hybrid Composer 1.4.6 Unauthenticated Settings ChangeEPSS 0.3%CVE-2026-80207MEDIUMAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Notification Create EndpointEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%CVE-2024-20391MEDIUMA vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical acceEPSS 0.3%CVE-2023-7328MEDIUMScreen SFT DAB 600/C <= 1.9.3 Unauthenticated Information DisclosureEPSS 0.3%CVE-2024-21824MEDIUMImproper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER IEPSS 0.3%CVE-2026-18111HIGHConcrete CMS below 9.5.4 allows privilege escalation because adding users and assigning groups do not require additional identity verificationEPSS 0.3%CVE-2026-76640HIGHUnitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning StackEPSS 0.3%CVE-2026-32291HIGHGL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial consoleEPSS 0.3%CVE-2026-60235HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.3%CVE-2024-49572HIGHA denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pEPSS 0.3%CVE-2025-20085HIGHA denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted EPSS 0.3%CVE-2026-60671HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). SupportEPSS 0.3%