Fallos del tipo CWE-306

2636 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-12490HIGHBypass of client certificate verification with transfer over TLSEPSS 0.2%CVE-2026-82930MEDIUMMissing Authentication in mH-DEVELOPEREPSS 0.2%CVE-2025-44039MEDIUMCP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability aEPSS 0.2%CVE-2026-50245HIGHBrickcom Cameras Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-66377HIGHPexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already hEPSS 0.2%CVE-2024-32765MEDIUMQTS, QuTS heroEPSS 0.2%CVE-2024-35295MEDIUMA vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between AprEPSS 0.2%CVE-2022-50979MEDIUMMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via Modbus (RS485)EPSS 0.2%CVE-2024-53701LOWMultiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to bEPSS 0.2%CVE-2026-86502HIGHIn JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote DeEPSS 0.2%CVE-2026-28468HIGHOpenClaw 2026.1.29-beta.1 < 2026.2.14 - Authentication Bypass in Sandbox Browser Bridge ServerEPSS 0.2%CVE-2026-24079HIGHMissing Authentication for Critical Function in Data ModemEPSS 0.2%CVE-2021-26278MEDIUMSensitive information leakage vulnerability in wifi moduleEPSS 0.2%CVE-2026-46555HIGHWhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationEPSS 0.2%CVE-2026-50608LOWAuthentication Vulnerability in NitroSense and PredatorSense SoftwareEPSS 0.2%CVE-2026-44211CRITICALCline Kanban Server has a Cross-Origin WebSocket Hijacking VulnerabilityEPSS 0.2%CVE-2025-48397HIGHThe privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed iEPSS 0.2%CVE-2026-84400LOWCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2022-50980MEDIUMMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via CANEPSS 0.2%CVE-2026-50604MEDIUMUnauthenticated Access Vulnerability in NitroSense and PredatorSense SoftwareEPSS 0.2%