Fallos del tipo CWE-306

2639 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-81441MEDIUMDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An EPSS 0.2%CVE-2025-62674HIGHMissing Authentication for RTSP in iCam CamerasEPSS 0.2%CVE-2024-22449MEDIUM Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileEPSS 0.2%CVE-2026-11238MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicEPSS 0.2%CVE-2026-60884MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.2%CVE-2026-6369MEDIUMExposed Session Token in canonical-livepatch client snapEPSS 0.2%CVE-2024-39707MEDIUMInsyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could leEPSS 0.2%CVE-2026-16646MEDIUMPanKM - Critical - Unsupported - SA-CONTRIB-2026-083EPSS 0.2%CVE-2026-33788HIGHJunos OS Evolved: Local, authenticated attacker can gain privileged access to FPCsEPSS 0.2%CVE-2026-32041HIGHOpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth BootstrapEPSS 0.2%CVE-2026-59913HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulneraEPSS 0.2%CVE-2020-12492LOWWifi information acquisition vulnerability in Framework ServicesEPSS 0.2%CVE-2025-67780MEDIUMSpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gREPSS 0.2%CVE-2026-42095MEDIUMbookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.EPSS 0.2%CVE-2025-12436MEDIUMPolicy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extensioEPSS 0.2%CVE-2023-52947MEDIUMMissing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3EPSS 0.2%CVE-2026-45610MEDIUMWWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FAEPSS 0.2%CVE-2026-24229HIGHNVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or EPSS 0.2%CVE-2024-2860HIGHThe PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker EPSS 0.2%CVE-2025-58318MEDIUMDIAView - Authentication Bypass VulnerabilityEPSS 0.2%