Fallos del tipo CWE-306

2635 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-0463HIGHThe force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022EPSS 0.2%CVE-2020-12484MEDIUMWhen using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprisEPSS 0.2%CVE-2026-57112HIGHPraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered toolsEPSS 0.2%CVE-2026-48106HIGHArc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peerEPSS 0.2%CVE-2026-85478LOWCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-13870LOWUnauthorized access and subscription vulnerability in BoardsEPSS 0.2%CVE-2025-40817HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.2%CVE-2025-11130HIGHiHongRen pptp-vpn XPC Service HelperTool.m shouldAcceptNewConnection missing authenticationEPSS 0.2%CVE-2025-3758HIGHExposure of Device Configuration without Authentication in WF2220EPSS 0.2%CVE-2026-84696CRITICALPhison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique CommandsEPSS 0.2%CVE-2025-47870MEDIUMTeam invite ID leaked to team admin with no member invite privilegesEPSS 0.2%CVE-2024-39364HIGHAdvantech ADAM-5630 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2026-10054HIGHIn affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shellEPSS 0.2%CVE-2025-10906HIGHMagnetism Studios Endurance NSXPC com.MagnetismStudios.endurance.helper loadModuleNamed:WithReply missing authenticationEPSS 0.2%CVE-2025-10672HIGHwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authenticationEPSS 0.2%CVE-2023-6215HIGHHP Sure Start IFD Protection - BIOS Security UpdateEPSS 0.2%CVE-2026-88956HIGHBotslab G980H Dashcams Missing Authentication for Critical FunctionEPSS 0.2%CVE-2026-12490HIGHBypass of client certificate verification with transfer over TLSEPSS 0.2%CVE-2024-47130HIGHMissing Authentication for Critical Function in goTenna ProEPSS 0.2%CVE-2026-44592CRITICALGradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoningEPSS 0.2%