Fallos del tipo CWE-306

2633 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-27892HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).EPSS 0.3%CVE-2026-69674MEDIUMWindows Modern Device Management (MDM) Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-72964MEDIUMWindows Internet Connection Sharing (ICS) Tampering VulnerabilityEPSS 0.3%CVE-2026-69554MEDIUMMicrosoft Windows Search Component Tampering VulnerabilityEPSS 0.3%CVE-2025-0257MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other servicesEPSS 0.3%CVE-2026-46997MEDIUMVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported vEPSS 0.3%CVE-2026-60908HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.3%CVE-2026-60781HIGHVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.3%CVE-2026-22924HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthentiEPSS 0.3%CVE-2026-72542MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-60623HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.3%CVE-2024-51362MEDIUMThe LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed thEPSS 0.3%CVE-2026-72541MEDIUMWindmill Labs Windmill - Missing AuthorizationEPSS 0.3%CVE-2026-6673MEDIUMMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installEPSS 0.3%CVE-2025-42926MEDIUMMissing Authentication check in SAP NetWeaver Application Server JavaEPSS 0.3%CVE-2026-69528HIGHWindows Shell Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50333HIGHWindows Spaceport.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50512HIGHMicrosoft PC Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61367HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26159HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%