Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-72577CRITICALNASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command InjectionEPSS 1.3%CVE-2026-20803HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2025-8286CRITICALGüralp Systems FMUS Series and MIN Series DevicesEPSS 1.3%CVE-2023-47674CRITICALMissing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite oEPSS 1.3%CVE-2026-9317CRITICALNango < 0.71.6 Missing Authentication RCE via runner tRPC serverEPSS 1.3%CVE-2023-28326CRITICALApache OpenMeetings: allows user impersonationEPSS 1.3%CVE-2026-72776CRITICALAgenticSeek Unauthenticated RCE via /query API EndpointEPSS 1.3%CVE-2022-26043HIGHAn external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform VEPSS 1.3%CVE-2022-26303HIGHAn external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.0EPSS 1.3%CVE-2021-43447HIGHONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attEPSS 1.3%CVE-2022-20858CRITICALCisco Nexus Dashboard Unauthorized Access VulnerabilitiesEPSS 1.3%CVE-2019-13525—In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to EPSS 1.3%CVE-2019-6820HIGHA CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IPEPSS 1.3%CVE-2020-12505HIGHWAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07EPSS 1.2%CVE-2020-10038—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attackEPSS 1.2%CVE-2022-39426HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 1.2%CVE-2026-75430CRITICALPowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the EPSS 1.2%CVE-2024-43488HIGHVisual Studio Code extension for Arduino Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-8320MEDIUMMissing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attaEPSS 1.2%CVE-2019-6533—Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway vEPSS 1.2%