Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-30762CRITICALImproper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS commanEPSS 0.7%CVE-2022-41644HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privilegesEPSS 0.7%CVE-2026-76157HIGHDatiphy Data Management Center - Missing Authentication for Critical FunctionEPSS 0.7%CVE-2023-53896HIGHD-Link DAP-1325 Hardware A1 Unauthenticated Configuration DownloadEPSS 0.7%CVE-2026-49973CRITICALHermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settingsEPSS 0.7%CVE-2026-94493CRITICALGigatech PDV5701 WebSocket Service index.html missing authenticationEPSS 0.7%CVE-2026-55640CRITICALNextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )EPSS 0.7%CVE-2020-10124—NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host EPSS 0.7%CVE-2026-81098CRITICALTelnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP TransportEPSS 0.7%CVE-2026-73849CRITICALemlog allows unauthenticated reinstallation via `install.php?action=reinstall`.EPSS 0.7%CVE-2026-53984HIGHGround Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Data Injection via Socket.IO database_backup full_restore ActionEPSS 0.7%CVE-2026-69415MEDIUMWindows DHCP Server Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2025-1701HIGHLocal Privilege Escalation in MIM Admin ServiceEPSS 0.7%CVE-2023-26573HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2026-23662HIGHAzure IoT Explorer Information Disclosure VulnerabilityEPSS 0.7%CVE-2026-6579MEDIUMliangliangyy DjangoBlog Clean Endpoint views.py missing authenticationEPSS 0.7%CVE-2026-78434MEDIUMFaveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authenticationEPSS 0.7%CVE-2026-6588MEDIUMserge-chat serge Model API Endpoint model.py delete_model missing authenticationEPSS 0.7%CVE-2026-79391CRITICALNo authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiEPSS 0.7%CVE-2024-8310CRITICALOPW Fuel Management Systems SiteSentinel Missing Authentication for Critical FunctionEPSS 0.7%