Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-25780MEDIUMStatus Internet Co.,Ltd. PowerBPM - Broken Access ControlEPSS 0.3%CVE-2025-3759HIGHMissing Authentication for Changing Device Configuration in WF2220EPSS 0.2%CVE-2026-32231HIGHZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload dataEPSS 0.2%CVE-2024-3219MEDIUMPure-Python fallback of socket.socketpair() doesn’t authenticate peer connectionEPSS 0.2%CVE-2021-32453MEDIUMSITEL CAP/PRX information exposureEPSS 0.2%CVE-2026-73588HIGHDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnEPSS 0.2%CVE-2026-57910CRITICALWatchGuard Agent improper authentication allows unauthenticated remote code executionEPSS 0.2%CVE-2026-12527MEDIUMA broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmwarEPSS 0.2%CVE-2026-47672MEDIUMepa4all-client: Unauthenticated REST API for Patient Record WritesEPSS 0.2%CVE-2022-48621MEDIUMVulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect EPSS 0.2%CVE-2021-23843HIGHLack of authentication mechanisms on the deviceEPSS 0.2%CVE-2025-54478HIGHUnauthenticated Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%CVE-2026-3194LOWChia Blockchain RPC Server Master Passphrase get_private_key missing authenticationEPSS 0.2%CVE-2024-6895MEDIUMInsecure Account Profile ManagementEPSS 0.2%CVE-2025-68716HIGHKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configuEPSS 0.2%CVE-2025-53034MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.2%CVE-2023-48426CRITICALChromecast Bootloader & Kernel-level code-execution including compromise of user-dataEPSS 0.2%CVE-2022-3312MEDIUMInsufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass manEPSS 0.2%CVE-2024-2104HIGHJBL: Improper BLE security configurations and lack of authentication on the device's GATT serverEPSS 0.2%