Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-62777HIGHWindows License Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-32326MEDIUMSHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the adminiEPSS 0.3%CVE-2026-26159HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61364HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50333HIGHWindows Spaceport.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26160HIGHRemote Desktop Licensing Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-42976HIGHRemote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-27169HIGHLack of authenticationEPSS 0.3%CVE-2025-27853HIGHThe locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performsEPSS 0.3%CVE-2026-11539MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.3%CVE-2026-11848HIGHIEI Integration Corp| iRM-IEI Remote Management - Missing AuthenticationEPSS 0.3%CVE-2025-55070MEDIUMLack of MFA enforcement in WebSocket connectionsEPSS 0.3%CVE-2026-44649CRITICALSillyTavern: Authentication Bypass via SSO Header InjectionEPSS 0.3%CVE-2024-26519CRITICALAn issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to theEPSS 0.3%CVE-2026-10283MEDIUMBottelet DaybydayCRM Setting missing authenticationEPSS 0.3%CVE-2025-62607MEDIUMNautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URLEPSS 0.3%CVE-2025-63896HIGHAn issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject EPSS 0.3%CVE-2026-46999HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). SupportEPSS 0.3%CVE-2026-31944HIGHLibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect linkEPSS 0.3%CVE-2020-26192HIGHDell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CEPSS 0.3%