Fallos del tipo CWE-306

2646 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-47122MEDIUMSparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injectionEPSS 0.1%CVE-2025-31963LOWHCL BigFix IVR is impacted by improper authentication and missing CSRF protectionEPSS 0.1%CVE-2026-86158HIGHMissing Authentication in the local .NET backend of Progress Telerik Fiddler EverywhereEPSS 0.1%CVE-2025-47357HIGHMissing Authentication for Critical Function in SMSSEPSS 0.1%CVE-2026-24088HIGHMissing Authentication for Critical Function in BootEPSS 0.1%CVE-2025-48608MEDIUMIn isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead toEPSS 0.1%CVE-2026-24090HIGHMissing Authentication for Critical Function in HLOSEPSS 0.1%CVE-2026-46711HIGHSoft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private networkEPSS —CVE-2026-102144MEDIUMKiteworks Email Protection Gateway Uncontrolled Resource ConsumptionEPSS —CVE-2026-102121HIGHKiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthorized ActorEPSS —CVE-2026-102458CRITICALDigiWin|EasyFlow .NET - Missing AuthenticationEPSS —CVE-2026-103270HIGHLightLLM through 1.2.0 Missing Authentication on RL Control RoutesEPSS —CVE-2026-93462MEDIUMMissing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility EPSS —CVE-2026-103053MEDIUMAiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action APIEPSS —CVE-2026-53988CRITICALDockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook EndpointsEPSS —CVE-2026-66083MEDIUMApache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasourceEPSS —CVE-2026-102110MEDIUMMissing authentication on a Kiteworks appliance setup functionEPSS —CVE-2026-103057MEDIUMAiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal EndpointsEPSS —CVE-2026-102124MEDIUMKiteworks Core Missing Authentication for Critical FunctionEPSS —CVE-2026-102150HIGHKiteworks Secure Data Forms Missing Authentication for Critical FunctionEPSS —