Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2021-36200MEDIUMMetasys ADS/ADX/OAS with MUIEPSS 0.7%CVE-2022-41688CRITICAL Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify useEPSS 0.7%CVE-2025-9983HIGHLack of Authentication for RTSP streamEPSS 0.7%CVE-2026-71289CRITICALNASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST APIEPSS 0.7%CVE-2022-24190HIGHThe /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is nEPSS 0.7%CVE-2026-2577CRITICALNanobot Unauthenticated WhatsApp Session Hijack via WebSocket BridgeEPSS 0.7%CVE-2022-21691MEDIUMImproper Access Control in OnionshareEPSS 0.7%CVE-2026-32646HIGHGardyn Cloud API Missing Authentication for Critical FunctionEPSS 0.7%CVE-2023-1083CRITICALWelotec: improper access control in TK500v1 router seriesEPSS 0.7%CVE-2022-45424MEDIUMSome Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key byEPSS 0.7%CVE-2026-4187MEDIUMTiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authenticationEPSS 0.7%CVE-2026-61613HIGHCursor: Cloud Agent Browser Sandbox EscapeEPSS 0.7%CVE-2026-65941HIGHWhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.EPSS 0.7%CVE-2025-66555HIGHAirKeyboard iOS App 1.0.5 - Remote Input InjectionEPSS 0.7%CVE-2024-8584CRITICALLEARNING DIGITAL Orca HCM - Missing AuthenticationEPSS 0.7%CVE-2025-15681CRITICALInsufficient Webserver AuthenticationEPSS 0.7%CVE-2026-26288CRITICALEveron api.everon.io Missing Authentication for Critical FunctionEPSS 0.7%CVE-2026-8031MEDIUMPicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authenticationEPSS 0.7%CVE-2025-71327CRITICALFlowise - Authentication Bypass via Unprotected Registration EndpointEPSS 0.7%CVE-2026-94151MEDIUMOmega Solution HRM OS Role Permission API permission missing authenticationEPSS 0.7%