Fallos del tipo CWE-306

2603 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-51987CRITICALD-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with emptyEPSS 0.9%CVE-2026-5944MEDIUMCisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API AccessEPSS 0.9%CVE-2016-6540—TrackR Bravo is missing authentication for the cloud service and allows querying or sending of GPS data from unauthenticated usersEPSS 0.9%CVE-2023-7329HIGHTinycontrol LAN Controller v3 (LK3) Remote DoSEPSS 0.9%CVE-2026-34072HIGHcronmaster: Middleware authentication bypass enabling unauthorized page access and server-action executionEPSS 0.9%CVE-2026-57123CRITICALPraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired inEPSS 0.9%CVE-2026-56163CRITICALMicrosoft Azure Kubernetes Service Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-43920MEDIUMFOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance executionEPSS 0.9%CVE-2016-9496—Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication to access certain pagesEPSS 0.9%CVE-2025-34068CRITICALSamsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 ParametersEPSS 0.9%CVE-2026-57127CRITICALpraisonai: recipe serve auth middleware silently disables itself when no secret is setEPSS 0.9%CVE-2023-27571MEDIUMAn issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download fuEPSS 0.9%CVE-2019-10915—A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA AEPSS 0.9%CVE-2021-34870MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_EPSS 0.9%CVE-2025-32978HIGHQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 0.9%CVE-2026-48252HIGHAdobe Experience Manager | Missing Authentication for Critical Function (CWE-306)EPSS 0.9%CVE-2024-33616MEDIUMAdmin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. SharpEPSS 0.9%CVE-2020-27285MEDIUMThe default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database withoutEPSS 0.9%CVE-2026-22552CRITICALePower epower.ie Missing Authentication for Critical FunctionEPSS 0.9%CVE-2026-75854CRITICALArcadeDB Redis Wire-Protocol Plugin Missing AuthenticationEPSS 0.9%