Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-93839CRITICALLightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket EndpointEPSS 0.8%CVE-2026-25084CRITICALZLAN Information Technology ZLAN5143D Missing Authentication for Critical FunctionEPSS 0.8%CVE-2017-6872—A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 2EPSS 0.8%CVE-2024-40717HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updaEPSS 0.8%CVE-2026-1775HIGHMissing Authentication for Critical Function in Labkotec LID-3300IPEPSS 0.8%CVE-2026-90513MEDIUMsimalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authenticationEPSS 0.8%CVE-2026-47281CRITICALVisual Studio Code Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-87924MEDIUMRizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authenticationEPSS 0.8%CVE-2026-86293MEDIUMSourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authenticationEPSS 0.8%CVE-2025-34071CRITICALGFI Kerio Control Unsigned System Image Upload Root Code ExecutionEPSS 0.8%CVE-2026-56262MEDIUMCrawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API ServerEPSS 0.8%CVE-2026-82472HIGHDocumenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdfEPSS 0.8%CVE-2024-22212CRITICALNextcloud global site selector authentication bypassEPSS 0.8%CVE-2026-25775CRITICALSenseLive X3050 Missing authentication for critical functionEPSS 0.8%CVE-2026-88018CRITICALrclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassEPSS 0.8%CVE-2026-57139CRITICALPraisonAI MCPServer exposes unauthenticated HTTP tools/callEPSS 0.8%CVE-2023-51947CRITICALImproper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types EPSS 0.8%CVE-2023-27497CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)EPSS 0.8%CVE-2026-85636MEDIUMjofpin trape Login Endpoint stats.py missing authenticationEPSS 0.8%CVE-2023-22069CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.8%