Fallos del tipo CWE-306

2600 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2020-3333MEDIUMCisco Application Services Engine Software Unauthenticated Event Policies Update VulnerabilityEPSS 1.0%CVE-2025-36535CRITICALAutomationDirect MB-Gateway Missing Authentication for Critical FunctionEPSS 1.0%CVE-2022-41272CRITICALAn unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NeEPSS 1.0%CVE-2024-9164CRITICALMissing Authentication for Critical Function in GitLabEPSS 1.0%CVE-2026-12046CRITICALpgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code executionEPSS 1.0%CVE-2026-57124CRITICALPraisonAI UI MCP connect endpoint allows unauthenticated local command executionEPSS 1.0%CVE-2019-13549—Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected syEPSS 1.0%CVE-2014-125113CRITICALDell/Quest KACE K1000 Unauthenticated File Upload RCEEPSS 1.0%CVE-2022-44784HIGHAn issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the AxEPSS 1.0%CVE-2017-6873—A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulatEPSS 1.0%CVE-2024-28179CRITICALJupyter Server Proxy's Websocket Proxying does not require authenticationEPSS 1.0%CVE-2026-26340HIGHTattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Stream DisclosureEPSS 1.0%CVE-2019-16004MEDIUMCisco Vision Dynamic Signage Director Authentication Bypass VulnerabilityEPSS 1.0%CVE-2025-27647CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users WitEPSS 1.0%CVE-2023-41187HIGHD-Link DAP-1325 HNAP Missing Authentication Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-27944CRITICALNginx UI: Unauthenticated Backup Download with Encryption Key DisclosureEPSS 1.0%CVE-2022-44000CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbEPSS 1.0%CVE-2022-43999CRITICALAn issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executeEPSS 1.0%CVE-2026-56164MEDIUMMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 1.0%KEVCVE-2026-3053MEDIUMDataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authenticationEPSS 1.0%