Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-94151MEDIUMOmega Solution HRM OS Role Permission API permission missing authenticationEPSS 0.7%CVE-2026-73666HIGHOpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/deleteEPSS 0.7%CVE-2025-7897MEDIUMharry0703 MoneyPrinterTurbo API Endpoint base.py verify_token missing authenticationEPSS 0.7%CVE-2026-8737MEDIUMSanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authenticationEPSS 0.7%CVE-2026-76639HIGHUnitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path TraversalEPSS 0.7%CVE-2024-9644CRITICALFour-Faith F3x36 bapply.cgi Auth BypassEPSS 0.7%CVE-2025-34069CRITICALGFI Kerio Control GFIAgent Authentication Bypass via Proxy ForwardingEPSS 0.7%CVE-2026-85889CRITICALAzure AI Foundry Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-44216HIGHGnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's originEPSS 0.7%CVE-2026-62241CRITICALclawvet < 0.7.5 Hard-coded JWT Secret Session ForgeryEPSS 0.7%CVE-2022-4980CRITICALGeneral Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin PageEPSS 0.7%CVE-2022-1070HIGHCHANNEL ACCESSIBLE BY NON-ENDPOINT CWE-300EPSS 0.7%CVE-2025-59695CRITICALEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user EPSS 0.7%CVE-2026-82787HIGHMissing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product maEPSS 0.7%CVE-2023-51571HIGHVoltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service VulnerabilityEPSS 0.7%CVE-2025-21515HIGHVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.7%CVE-2026-29796CRITICALIGL-Technologies eParking.fi Missing Authentication for Critical FunctionEPSS 0.7%CVE-2026-55678MEDIUMArc: Unauthenticated cluster node admission when `cluster.shared_secret` is unsetEPSS 0.7%CVE-2026-5724MEDIUMMissing Authentication on Streaming gRPC Replication EndpointEPSS 0.7%CVE-2025-34207HIGHVasion Print (formerly PrinterLogic) Insecure SSH Client ConfigurationEPSS 0.7%