Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-57969HIGHAzure CycleCloud Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-5951HIGHDeep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service VulnerabilityEPSS 0.8%CVE-2026-50444HIGHWindows Server Update Service (WSUS) Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2023-38379—The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin passworEPSS 0.8%CVE-2025-55108CRITICALBMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code executionEPSS 0.8%CVE-2025-59358HIGHDenial of Service via Unauthorized Access to Chaos Mesh debugging serverEPSS 0.8%CVE-2024-47138CRITICALmySCADA myPRO Missing Authentication for Critical FunctionEPSS 0.8%CVE-2025-9574CRITICALMissing Authentication VulnerabilityEPSS 0.8%CVE-2026-77915CRITICALrConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.phpEPSS 0.8%CVE-2026-84839MEDIUMtsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authenticationEPSS 0.8%CVE-2026-54103CRITICALU.S. GAO EPDS and CBCA EDS unauthenticated password changeEPSS 0.8%CVE-2026-9336MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.8%CVE-2018-25412CRITICALDelta Sql 1.8.2 Arbitrary File Upload via docs_upload.phpEPSS 0.8%CVE-2025-14567MEDIUMhaxxorsid Stock-Management-System employees missing authenticationEPSS 0.8%CVE-2026-91002MEDIUMstamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authenticationEPSS 0.8%CVE-2026-26944HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 0.8%CVE-2026-78239CRITICALXiiaozet LK100W Missing Authentication for Critical FunctionEPSS 0.8%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2026-15192MEDIUMmettle sendportal APIv1 Webhooks mailjet missing authenticationEPSS 0.8%CVE-2026-4959MEDIUMOpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authenticationEPSS 0.8%