Fallos del tipo CWE-306

2639 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-4516HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker tEPSS 0.2%CVE-2026-75060HIGHIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP toolsEPSS 0.2%CVE-2025-0129CRITICALPrisma Access Browser: Inappropriate control behavior in Prisma Access BrowserEPSS 0.2%CVE-2026-24259MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A succeEPSS 0.2%CVE-2025-55581HIGHD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. EPSS 0.2%CVE-2026-1264HIGHIBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access ControlsEPSS 0.2%CVE-2025-54158HIGHMissing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local userEPSS 0.2%CVE-2026-4522MEDIUMMissing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affeEPSS 0.2%CVE-2024-55538MEDIUMSensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before buildEPSS 0.2%CVE-2025-64770HIGHMissing Authentication for ONVIF in iCam CamerasEPSS 0.2%CVE-2025-12444MEDIUMIncorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in sEPSS 0.2%CVE-2023-52949MEDIUMMissing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent befoEPSS 0.2%CVE-2025-30039CRITICALMissing authentication in API returning a list of all active sessionsEPSS 0.2%CVE-2025-30041CRITICALMissing authentication in APIs returning statistical data along with session IDsEPSS 0.2%CVE-2025-12447MEDIUMIncorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engageEPSS 0.2%CVE-2026-55529MEDIUMPraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP serverEPSS 0.2%CVE-2025-10991HIGHRoot Access via UARTEPSS 0.2%CVE-2025-15515MEDIUMThe authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a loEPSS 0.2%CVE-2026-96455HIGHReachy Mini daemon allows unauthenticated remote code execution through the app installation endpointEPSS 0.2%CVE-2025-62674HIGHMissing Authentication for RTSP in iCam CamerasEPSS 0.2%