Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-1840HIGHMissing authentication for critical function in Hubbell Aclara Metrum Cellular Web InterfaceEPSS 0.7%CVE-2021-37696HIGHSensitive information leak in MassDM of tmerc-cogsEPSS 0.7%CVE-2026-13164HIGHUnauthenticated self-registration in MailerUp allows access to stored email dataEPSS 0.7%CVE-2026-73173HIGHNozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol oEPSS 0.7%CVE-2023-0052CRITICALSAUTER Controls Nova 200–220 Series Missing Authentication for Critical FunctionEPSS 0.7%CVE-2025-30410CRITICALSensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud AEPSS 0.7%CVE-2026-11420CRITICALPath Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File ReadEPSS 0.7%CVE-2026-16209MEDIUMGerapy Project Upload Endpoint views.py missing authenticationEPSS 0.7%CVE-2024-3777CRITICALAi3 QbiBot - Broken Access ControlEPSS 0.7%CVE-2023-22804CRITICALCVE-2023-22804EPSS 0.7%CVE-2025-63389CRITICALA critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The plaEPSS 0.7%CVE-2026-9141CRITICALTaiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web InterfaceEPSS 0.7%CVE-2026-53985HIGHGround Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IOEPSS 0.7%CVE-2017-20222HIGHTelesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote RebootEPSS 0.7%CVE-2026-81475HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An EPSS 0.7%CVE-2022-43976CRITICALAn issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API iEPSS 0.7%CVE-2026-85663CRITICALAim 3.29.1 Remote Code Execution via Unauthenticated Method DispatchEPSS 0.7%CVE-2025-4019MEDIUM20120630 Novel-Plus GeneratorController.java genCode missing authenticationEPSS 0.7%CVE-2026-58446MEDIUMPresenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP EndpointEPSS 0.7%CVE-2026-63765HIGHChatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob CreationEPSS 0.7%