Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-6592CRITICALWatchGuard Firebox Single Sign-On Agent Protocol Authorization BypassEPSS 1.2%CVE-2025-32896MEDIUMApache SeaTunnel: Unauthenticated insecure accessEPSS 1.2%CVE-2023-49693CRITICALNETGEAR ProSAFE Network Management System RCE via Unprotected Access to Java Debug Wire ProtocolEPSS 1.2%CVE-2021-33008HIGHAVEVA System Platform Missing Authentication for Critical FunctionEPSS 1.2%CVE-2020-3376HIGHCisco Data Center Network Manager Authentication Bypass VulnerabilityEPSS 1.2%CVE-2025-34130HIGHLILIN DVR Arbitrary File Read via net_html.cgiEPSS 1.1%CVE-2026-23693CRITICALElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST EndpointEPSS 1.1%CVE-2026-11429CRITICALPath Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code ExecutionEPSS 1.1%CVE-2022-28771—Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send maliciouEPSS 1.1%CVE-2025-34215CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Firmware Update Endpoint RCEEPSS 1.1%CVE-2026-27446CRITICALApache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federationEPSS 1.1%CVE-2018-14796—Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be usedEPSS 1.1%CVE-2025-21623HIGHClipBucket V5 Unauthenticated Template Directory Update to Denial-of-ServiceEPSS 1.1%CVE-2019-18230—Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticatEPSS 1.1%CVE-2020-10605—Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.EPSS 1.1%CVE-2023-27747HIGHBlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access seEPSS 1.1%CVE-2023-21743MEDIUMMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2023-36851MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary filesEPSS 1.1%KEVCVE-2022-38168CRITICALBroken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackEPSS 1.1%CVE-2026-86121CRITICALCua computer-server before 0.3.42 Unauthenticated RCE via Desktop ControlEPSS 1.1%