Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-84423MEDIUMCasdoor upload-resource API resource.go missing authenticationEPSS 0.7%CVE-2026-81202MEDIUMitsourcecode Payroll System CRUD Operation ajax.php delete missing authenticationEPSS 0.7%CVE-2026-5676MEDIUMTotolink A8000R cstecgi.cgi setLanguageCfg missing authenticationEPSS 0.7%CVE-2026-18265CRITICALOSNEXUS QuantaStor Missing Authentication Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-0102CRITICALCVE-2023-0102EPSS 0.7%CVE-2025-34220MEDIUMVasion Print (formerly PrinterLogic) Unauthenticated API Leaks Group InformationEPSS 0.7%CVE-2026-14622MEDIUMjairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authenticationEPSS 0.7%CVE-2025-70141CRITICALSourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enfoEPSS 0.7%CVE-2026-54670CRITICALWeGIA: Unauthenticated Auth Bypass + Local File InclusionEPSS 0.7%CVE-2024-27942HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to diEPSS 0.7%CVE-2026-78369HIGHMissing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLookEPSS 0.7%CVE-2026-55642CRITICALdbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured)EPSS 0.7%CVE-2022-50593CRITICALAdvantech iView < v5.7.04 Build 6425 search_term Parameter SQL Injection RCEEPSS 0.7%CVE-2026-87922MEDIUMRizwan17 inventory-management-system AJAX Backend process.php DBOperation.addCategory missing authenticationEPSS 0.7%CVE-2026-86292MEDIUMSourceCodester Simple Traffic Offense System User Creation saveuser.php missing authenticationEPSS 0.7%CVE-2026-16210MEDIUMnewpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authenticationEPSS 0.7%CVE-2026-6126MEDIUMzhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authenticationEPSS 0.7%CVE-2026-18990MEDIUMletta-ai LettaBot API Status Route server.ts missing authenticationEPSS 0.7%CVE-2026-56299MEDIUMCapgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload EndpointEPSS 0.7%CVE-2021-36200MEDIUMMetasys ADS/ADX/OAS with MUIEPSS 0.7%