Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-82693CRITICALTenda AC1206 Web UI telnet TendaTelnet missing authenticationEPSS 1.4%CVE-2026-82694CRITICALTenda AC1206 Web UI ate R7WebsSecurityHandler missing authenticationEPSS 1.4%CVE-2023-5376HIGHTFTP Without AuthenticationEPSS 1.4%CVE-2026-82695CRITICALTenda AC18 Telnet telnet missing authenticationEPSS 1.4%CVE-2021-27255MEDIUMThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. AEPSS 1.4%CVE-2019-13933—A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRPEPSS 1.4%CVE-2020-5373MEDIUMDell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentEPSS 1.4%CVE-2020-5328CRITICALDell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks whEPSS 1.4%CVE-2026-45087CRITICALDalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server ModeEPSS 1.4%CVE-2019-5152HIGHAn exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utiEPSS 1.4%CVE-2020-15127HIGHDenial of service in ContourEPSS 1.4%CVE-2023-27396CRITICALFINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)EPSS 1.4%CVE-2020-6964—In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X EPSS 1.4%CVE-2022-40202CRITICAL The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attEPSS 1.3%CVE-2022-26067MEDIUMAn information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform EPSS 1.3%CVE-2026-94493CRITICALGigatech PDV5701 WebSocket Service index.html missing authenticationEPSS 1.3%CVE-2025-12548CRITICALGithub.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333EPSS 1.3%CVE-2026-25938CRITICALFUXA Unauthenticated Remote Code Execution in Node-RED IntegrationEPSS 1.3%CVE-2025-6763CRITICALComet System H3531 Web-based Management setupA.cfg missing authenticationEPSS 1.3%CVE-2026-42569CRITICALphpvms: /importer authorization bypass causing full database wipeEPSS 1.3%