Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-26027HIGHGLPI has an Unauthenticated Stored XSS via inventoryEPSS 0.3%CVE-2025-65828MEDIUMAn unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these deviEPSS 0.3%CVE-2026-5300MEDIUMMissing Authentication for Critical Function in coolercontroldEPSS 0.3%CVE-2024-48952MEDIUMAn issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoinEPSS 0.3%CVE-2026-15063MEDIUMTrustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabledEPSS 0.3%CVE-2025-8450HIGHUnrestricted File Upload in FileCatalystEPSS 0.3%CVE-2024-54176MEDIUMIBM UrbanCode Deploy missing authenticationEPSS 0.3%CVE-2026-100876MEDIUMmathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenticationEPSS 0.3%CVE-2026-83252HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-9033MEDIUMUnauthenticated Captive Portal Session Termination and Forced Logout in Omada GatewaysEPSS 0.3%CVE-2022-25770HIGHInsufficient authentication in upgrade flowEPSS 0.3%CVE-2025-27256HIGHMissing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to EPSS 0.3%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.3%CVE-2026-102363MEDIUMmall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order NumberEPSS 0.3%CVE-2025-13778HIGHDevice Reboot ControlEPSS 0.3%CVE-2025-36756MEDIUMDevice Takeover vulnerability in SolaX CloudEPSS 0.3%CVE-2026-81238HIGHDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unautheEPSS 0.3%CVE-2026-55837MEDIUMdbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensEPSS 0.3%CVE-2025-10746MEDIUMIntegrate Dynamics 365 CRM <= 1.0.9 - Missing AuthorizationEPSS 0.3%CVE-2019-25678HIGHC4G BLIS 3.4 SQL Injection via users_select.phpEPSS 0.3%