Fallos del tipo CWE-306

2634 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-2104HIGHJBL: Improper BLE security configurations and lack of authentication on the device's GATT serverEPSS 0.2%CVE-2026-6017HIGHMissing Authentication for Critical Function in KAON PG5298EPSS 0.2%CVE-2026-24177HIGHNVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of thEPSS 0.2%CVE-2025-9312CRITICALImproper Certificate-Based Authentication Enforcement in Multiple WSO2 ProductsEPSS 0.2%CVE-2025-1272HIGHKernel: secure boot does not automatically enable kernel lockdownEPSS 0.2%CVE-2025-5719MEDIUMThe wallet has an authentication bypass vulnerability that allows access to specific pages.EPSS 0.2%CVE-2026-93539MEDIUMUnauthenticated GitRepo Spec Mutation via Fleet Git Webhook ReceiverEPSS 0.2%CVE-2026-8706MEDIUMSensitive user data could be leaked to other applications through Reader modeEPSS 0.2%CVE-2026-71568MEDIUMBMCtest exposes Ironic without authentication and TLS during the testEPSS 0.2%CVE-2024-45483HIGHMissing GRUB password in B&R APROLEPSS 0.2%CVE-2025-64307HIGHBrightpick Mission Control / Internal Logic Control Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-14038HIGHEDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an atEPSS 0.2%CVE-2026-1920MEDIUMBooktics <= 1.0.16 - Missing Authorization to Addon Plugin InstallationEPSS 0.2%CVE-2025-23293HIGHNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.2%CVE-2024-31684LOWIncorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fEPSS 0.2%CVE-2023-47232MEDIUMWordPress WP Affiliate Disclosure plugin <= 1.2.6 - Broken Access Control + CSRF vulnerabilityEPSS 0.2%CVE-2024-47555HIGHMissing Authentication - User & System ConfigurationEPSS 0.2%CVE-2026-78306HIGHDJI Drone Bluetooth Interface Unauthenticated DUML Command ExecutionEPSS 0.2%CVE-2025-64056MEDIUMFile upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the fiEPSS 0.2%CVE-2023-0463HIGHThe force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022EPSS 0.2%