Fallos del tipo CWE-306

2638 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-32460HIGH Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially eEPSS 0.2%CVE-2018-25224HIGHPMS 0.42 Stack-Based Buffer Overflow via Configuration FileEPSS 0.2%CVE-2026-42312MEDIUMpyload-ng: non-admin SETTINGS users can disable outbound TLS peer verificationEPSS 0.2%CVE-2020-12491MEDIUMFramework Information Disclosure VulnerabilityEPSS 0.2%CVE-2018-25259HIGHTerminal Services Manager 3.1 Buffer Overflow SEHEPSS 0.2%CVE-2026-12910MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.2%CVE-2024-35342MEDIUMCertain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, EPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.2%CVE-2025-15481MEDIUMNotification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data DisclosureEPSS 0.2%CVE-2021-26264MEDIUMEmerson DeltaV Missing Authentication for Critical FunctionEPSS 0.2%CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.2%CVE-2026-85981MEDIUMUnauthenticated Localhost Admin Panel in Auth0 AD/LDAP ConnectorEPSS 0.2%CVE-2026-11838MEDIUMImproper Authorization in Yordam Informatics' Library Reservation SystemEPSS 0.2%CVE-2025-65010HIGHMissing authorizations for admin panel password change in WODESYS WD-R608U routerEPSS 0.2%CVE-2025-55073MEDIUMMS Teams plugin OAuth allows editing arbitrary postsEPSS 0.2%CVE-2026-60600HIGHVulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version tEPSS 0.2%CVE-2025-30040CRITICALMissing authentication in API returning request logs containing session IDsEPSS 0.2%CVE-2023-4516HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker tEPSS 0.2%CVE-2023-25493MEDIUMA potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products EPSS 0.2%CVE-2026-6348CRITICALSimopro Technology|WinMatrix - Missing AuthenticationEPSS 0.2%