Fallos del tipo CWE-306

2639 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-2860HIGHThe PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker EPSS 0.2%CVE-2024-12957HIGHA file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 SEPSS 0.2%CVE-2026-60596LOWVulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version EPSS 0.2%CVE-2025-14058LOWA potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical accEPSS 0.2%CVE-2023-5935HIGHMissing authentication for local web interface in Arc before v1.6.0EPSS 0.2%CVE-2025-47272MEDIUMPhoenixCart Vulnerable to Account Deletion Without Password ConfirmationEPSS 0.2%CVE-2026-94540HIGHDesktopSMS 1.11.0 Unauthorized Access via Local ServiceEPSS 0.2%CVE-2024-45356HIGHXiaomi phone framework has unauthorized access vulnerabilityEPSS 0.2%CVE-2026-76137MEDIUMMissing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a rEPSS 0.2%CVE-2026-39848MEDIUMDockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database ManipulationEPSS 0.2%CVE-2026-60712MEDIUMVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.2%CVE-2026-60595MEDIUMVulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The suppoEPSS 0.2%CVE-2026-0247MEDIUMPrisma Access Agent Endpoint DLP: Authorization Bypass VulnerabilitiesEPSS 0.2%CVE-2026-54776MEDIUMCoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgradeEPSS 0.2%CVE-2021-26280HIGHPermission bypass vulnerability in permission manager moduleEPSS 0.2%CVE-2026-11535CRITICALAn unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to thEPSS 0.2%CVE-2026-42283HIGHDevSpace UI Server WebSocket CheckOrigin does not validate sourceEPSS 0.1%CVE-2026-9045HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise foEPSS 0.1%CVE-2026-12763MEDIUMLangflow is vulnerable to authentication bypass and insufficient session expirationEPSS 0.1%CVE-2026-46685MEDIUMRustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on consoleEPSS 0.1%