Fallos del tipo CWE-306

2632 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-71203MEDIUMchangedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI SchemaEPSS 0.3%CVE-2025-23194MEDIUMMissing Authentication check in SAP NetWeaver Enterprise Portal (OBN component)EPSS 0.3%CVE-2026-12989HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.3%CVE-2026-8335HIGHMissing authentication in Aix-DBEPSS 0.3%CVE-2025-32782MEDIUMAsh Authentication email link auto-click account confirmation vulnerabilityEPSS 0.3%CVE-2026-5777HIGHSecurity Misconfiguration Vulnerability in Atom 3x ProjectorEPSS 0.3%CVE-2024-9919HIGHMissing Authentication Check in parisneo/lollms-webuiEPSS 0.3%CVE-2025-61778CRITICALAkka.Remote TLS did not properly implement certificate-based authenticationEPSS 0.3%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2025-13030MEDIUMAll versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An EPSS 0.3%CVE-2026-59804HIGHMidscene Bridge Server - Session Hijack via Unauthenticated WebSocketEPSS 0.3%CVE-2026-61267HIGHVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versEPSS 0.3%CVE-2025-42885MEDIUMMissing authentication in SAP HANA 2.0 (hdbrss)EPSS 0.3%CVE-2026-50451HIGHWindows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-31033MEDIUMCVEEPSS 0.3%CVE-2025-7031MEDIUMConfig Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086EPSS 0.3%CVE-2025-12349MEDIUMEmail Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue TriggerEPSS 0.3%CVE-2026-83991MEDIUMWindows Cloud Files Mini Filter Driver Tampering VulnerabilityEPSS 0.3%CVE-2026-73004MEDIUMWindows Autopilot Tampering VulnerabilityEPSS 0.3%CVE-2024-27892HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).EPSS 0.3%