Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-0274MEDIUMHCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2025-1754MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.3%CVE-2026-62474MEDIUMVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versionEPSS 0.3%CVE-2026-59148HIGHMockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftEPSS 0.3%CVE-2026-60574MEDIUMVulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affecEPSS 0.3%CVE-2026-81455HIGHDell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An uEPSS 0.3%CVE-2024-6347MEDIUMUnauthorized access to ECU functionalityEPSS 0.3%CVE-2026-1919MEDIUMBooktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpointsEPSS 0.3%CVE-2025-48572HIGHIn multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to locaEPSS 0.3%KEVCVE-2025-1495MEDIUMIBM Business Automation Workflow missing authenticationEPSS 0.3%CVE-2025-7706MEDIUMImproper Access Control in TUBITAK BILGEM's LiderahenkEPSS 0.3%CVE-2026-54040MEDIUMLibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA BypassEPSS 0.3%CVE-2026-50025MEDIUMMousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie stateEPSS 0.3%CVE-2024-48442MEDIUMIncorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows aEPSS 0.3%CVE-2022-45190MEDIUMAn issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing EPSS 0.3%CVE-2024-56469MEDIUMIBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authenticationEPSS 0.3%CVE-2026-77339MEDIUMProcess Compose: Browser DNS rebinding lets websites control local process-compose MCP toolsEPSS 0.3%CVE-2025-15509HIGHThe SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.EPSS 0.3%CVE-2026-52748HIGHMissing authentication for backup functionality in Kaon AR2140XEPSS 0.3%CVE-2026-57128MEDIUMPraisonAI: Unauthenticated Event Injection via SSE `/publish` EndpointEPSS 0.3%