Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2019-25678HIGHC4G BLIS 3.4 SQL Injection via users_select.phpEPSS 0.3%CVE-2026-60682MEDIUMVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that isEPSS 0.3%CVE-2026-76902MEDIUMCordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`EPSS 0.3%CVE-2026-60322MEDIUMVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported vEPSS 0.3%CVE-2025-0256MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosureEPSS 0.3%CVE-2025-11198HIGHSecurity Director Policy Enforcer: An unrestricted API allows a network-based unauthenticated attacker to deploy malicious vSRX images to VMWare NSX ServerEPSS 0.3%CVE-2026-61247MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.3%CVE-2026-49174MEDIUMDNS Client Tampering VulnerabilityEPSS 0.3%CVE-2026-22192HIGHVoltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorageEPSS 0.3%CVE-2026-73842CRITICALOpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutationEPSS 0.3%CVE-2024-57055MEDIUMServer-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain servEPSS 0.3%CVE-2025-9815HIGHalaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authenticationEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.3%CVE-2026-77974HIGHSoftish C6 Ear Camera and EarVision Android Application Missing authentication for critical functionEPSS 0.3%CVE-2026-13306MEDIUMAutel MaxiCharger AC Elite Home USB Authentication Bypass VulnerabilityEPSS 0.3%CVE-2025-30035CRITICALLack of API authentication allowing session generation for any userEPSS 0.3%CVE-2025-1754MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.3%CVE-2026-94455HIGHUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API keyEPSS 0.3%CVE-2025-0275MEDIUMHCL BigFix Mobile 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2025-0274MEDIUMHCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access controlEPSS 0.3%