Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-21855CRITICALA lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arEPSS 2.0%CVE-2023-39457CRITICALTriangle MicroWorks SCADA Data Gateway Missing Authentication VulnerabilityEPSS 2.0%CVE-2023-2231CRITICALMAXTECH MAX-G866ac Remote Management missing authenticationEPSS 2.0%CVE-2019-18572HIGHThe RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper AuthenticatioEPSS 2.0%CVE-2020-7589—A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker readinEPSS 2.0%CVE-2015-7559LOWIt was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker loEPSS 2.0%CVE-2026-26235HIGHJUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing AuthenticationEPSS 2.0%CVE-2014-9197—Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical FunctionEPSS 2.0%CVE-2025-34110CRITICALColoradoFTP Server <= 1.3 Build 8 Path Traversal Information DisclosureEPSS 1.9%CVE-2022-39412HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affEPSS 1.9%CVE-2026-32985CRITICALXerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code ExecutionEPSS 1.9%CVE-2026-58127CRITICALPACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP ServiceEPSS 1.9%CVE-2022-25251CRITICALPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 1.9%CVE-2022-35865HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication EPSS 1.9%CVE-2026-8732CRITICALWP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX ActionEPSS 1.9%CVE-2026-58126CRITICALPACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP ServiceEPSS 1.8%CVE-2021-20198—A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift ConEPSS 1.8%CVE-2024-8321MEDIUMMissing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attaEPSS 1.8%CVE-2025-34120HIGHLimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup PayloadEPSS 1.8%CVE-2021-32800HIGHBypass of Two Factor Authentication in Nextcloud serverEPSS 1.8%