Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-10772MEDIUMhuggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authenticationEPSS 0.3%CVE-2026-60705HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2020-3335MEDIUMCisco Application Services Engine Software Authorization VulnerabilityEPSS 0.3%CVE-2024-10649MEDIUMUnauthenticated File Upload in wandb/openuiEPSS 0.3%CVE-2026-50136HIGHBudibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialsEPSS 0.3%CVE-2026-28485HIGHOpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP EndpointsEPSS 0.3%CVE-2026-47038LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0EPSS 0.3%CVE-2018-25437HIGHWordPress CherryFramework Themes 3.1.4 Backup File DownloadEPSS 0.3%CVE-2026-76444MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-102362MEDIUMmall4j through 4.0 Missing Authentication in Product Review DeletionEPSS 0.3%CVE-2025-13779HIGHConfiguration Data SpillEPSS 0.3%CVE-2024-36457MEDIUMSymantec Privileged Access Manager Authentication Bypass vulnerabilityEPSS 0.3%CVE-2023-2827HIGHMissing Authentication in SAP Plant Connectivity and Production Connector for SAP DigitalEPSS 0.3%CVE-2025-6920MEDIUMAi-inference-server: authentication bypass via unprotected inference endpoint in apiEPSS 0.3%CVE-2024-35585HIGHOxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.EPSS 0.3%CVE-2025-53847MEDIUMA missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7EPSS 0.3%CVE-2026-49994CRITICALBluehood: Missing authentication on Bluehood API routes when web auth is enabledEPSS 0.3%CVE-2026-60616MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.3%CVE-2024-40408HIGHCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. ThisEPSS 0.3%CVE-2026-46409CRITICALOpenYak local API: unauthenticated CSRF chain leads to Remote Code ExecutionEPSS 0.3%