Fallos del tipo CWE-306

2646 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-60569MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0EPSS 0.1%CVE-2024-45355MEDIUMXiaomi phone framework has unauthorized access vulnerabilityEPSS 0.1%CVE-2024-9062HIGHmacOS Archify: Local Privilege EscalationEPSS 0.1%CVE-2026-70806HIGHVulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.1%CVE-2026-92254MEDIUMWatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTLEPSS 0.1%CVE-2026-70693MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.1%CVE-2025-30650HIGHJunos OS: Privileged local user can gain access to a Linux-based FPC as rootEPSS 0.1%CVE-2025-15567MEDIUMInsufficient protection mechanisms in the Health Module may lead to partial information disclosure.EPSS 0.1%CVE-2026-6511MEDIUMDuring an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for WindowsEPSS 0.1%CVE-2025-41686HIGHImproper File Permissions Allow Local Privilege EscalationEPSS 0.1%CVE-2026-60902HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affectEPSS 0.1%CVE-2026-70711LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.1%CVE-2026-60975HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affeEPSS 0.1%CVE-2019-25483HIGHComtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell EscapeEPSS 0.1%CVE-2026-22174MEDIUMOpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP ProbeEPSS 0.1%CVE-2026-19267MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2026-84403MEDIUMBotslab G980H Dashcams Missing Authentication for Critical FunctionEPSS 0.1%CVE-2026-24062HIGHInsufficient XPC Client validation leading to local privilege escalation in Arturia Software CenterEPSS 0.1%CVE-2026-12663HIGHControlFLASH ® – Improper Access ControlEPSS 0.1%CVE-2026-21767MEDIUMHCL BigFix Platform is affected by insufficient authenticationEPSS 0.1%