Fallos del tipo CWE-306

2600 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-3053MEDIUMDataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authenticationEPSS 1.0%CVE-2026-93839CRITICALLightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket EndpointEPSS 1.0%CVE-2021-26928MEDIUMBIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which mEPSS 1.0%CVE-2026-21992CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services ManagEPSS 1.0%CVE-2026-32211CRITICALAzure MCP Server Information Disclosure VulnerabilityEPSS 1.0%CVE-2025-34218CRITICALVasion Print (formerly PrinterLogic) Exposed Internal Docker InstanceEPSS 1.0%CVE-2020-14140HIGHWhen Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerabilEPSS 1.0%CVE-2020-10754MEDIUMIt was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when cEPSS 1.0%CVE-2016-10364—With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL servEPSS 1.0%CVE-2026-3611CRITICALHoneywell IQ4x BMS Controller Missing authentication for critical functionEPSS 1.0%CVE-2026-86124CRITICALAutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command ServerEPSS 1.0%CVE-2023-22441HIGHMissing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alteEPSS 1.0%CVE-2023-53964HIGHSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset VulnerabilityEPSS 1.0%CVE-2024-36445CRITICALSwissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.EPSS 1.0%CVE-2026-68502CRITICALLazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCEEPSS 1.0%CVE-2026-57131CRITICALpraisonai: Jobs API exposes agent-execution endpoints with no authenticationEPSS 1.0%CVE-2023-53771CRITICALMiniDVBLinux 5.4 Unauthenticated Root Password Change via System SetupEPSS 1.0%CVE-2026-0625CRITICALD-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration EndpointEPSS 1.0%CVE-2025-34224CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Device ModificationEPSS 1.0%CVE-2026-53977HIGHOpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdownEPSS 1.0%