Fallos del tipo CWE-306

2632 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-44830HIGHEmpty API_TOKEN disables authentication on network-reachable HTTP/SSE transportEPSS 0.3%CVE-2025-12476CRITICALResource Lacking AuthNEPSS 0.3%CVE-2025-42875MEDIUMMissing Authentication check in SAP NetWeaver Internet Communication FrameworkEPSS 0.3%CVE-2025-51543CRITICALAn issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_pEPSS 0.3%CVE-2026-75754CRITICALMissing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center aEPSS 0.3%CVE-2025-65007HIGHMissing Authentication for Critical Function in WODESYS WD-R608U routerEPSS 0.3%CVE-2026-82784MEDIUMMissing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may exEPSS 0.3%CVE-2022-27495MEDIUMOn all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: SoftwareEPSS 0.3%CVE-2026-61135HIGHVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.3%CVE-2026-87195HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2026-60856HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packaging). Supported versions EPSS 0.3%CVE-2025-4382MEDIUMGrub2: grub allow access to encrypted device through cli once root device is unlocked via tpmEPSS 0.3%CVE-2025-41090HIGHImproper Access Control in CCN-CERT microCLAUDIAEPSS 0.3%CVE-2025-4560MEDIUMNetvision ISOinsight - Missing AuthenticationEPSS 0.3%CVE-2024-41968MEDIUMWAGO: Docker Settings Manipulation in Multiple DevicesEPSS 0.3%CVE-2026-54246MEDIUMSkipper routesrv-no-auth: All routesrv API Endpoints Lack AuthenticationEPSS 0.3%CVE-2025-15346CRITICALwolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirementEPSS 0.3%CVE-2025-30126MEDIUMAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remoEPSS 0.3%CVE-2025-25068HIGHBypassing MFA Enforcement on Plugin EndpointsEPSS 0.3%CVE-2025-11728MEDIUMOceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status UpdateEPSS 0.3%