Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2021-36779CRITICALHost operations allowed in privileged Longhorn managed podsEPSS 0.7%CVE-2026-0611CRITICALSpacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET RemotingEPSS 0.7%CVE-2026-75852CRITICALArcadeDB MongoDB wire protocol authentication bypass cross-databaseEPSS 0.7%CVE-2026-44668CRITICALFaction: Unauthenticated Read, Modify, and Delete of Boilerplate TemplatesEPSS 0.7%CVE-2023-26580HIGHMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.7%CVE-2017-20217HIGHServiio PRO 1.8 REST API Information DisclosureEPSS 0.7%CVE-2023-41186MEDIUMD-Link DAP-1325 CGI Missing Authentication Information Disclosure VulnerabilityEPSS 0.7%CVE-2026-90944HIGHKrayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parseEPSS 0.7%CVE-2026-31881HIGHRuntipi unauthenticated /api/auth/reset-password allows operator account takeover during active reset windowEPSS 0.7%CVE-2022-43110CRITICALVoltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system viaEPSS 0.7%CVE-2023-31143MEDIUMMage terminal user authentication not working properlyEPSS 0.7%CVE-2023-0906HIGHSourceCodester Online Pizza Ordering System POST Parameter ajax.php delete_category missing authenticationEPSS 0.7%CVE-2025-59097CRITICALUnauthenticated SOAP API in dormakaba access managerEPSS 0.7%CVE-2026-92625HIGHControl iD iDSecure Unauthenticated Denial of ServiceEPSS 0.7%CVE-2026-85702MEDIUMramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authenticationEPSS 0.7%CVE-2026-3893CRITICALCarlson Software VASCO-B GNSS Receiver Missing Authentication for Critical FunctionEPSS 0.7%CVE-2026-55814HIGHApache Ranger: Download APIs expose plugin data without authenticationEPSS 0.7%CVE-2026-46612HIGHFission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archivesEPSS 0.7%CVE-2026-28814HIGHApache JSPWiki: Pre-Authentication Arbitrary Wiki Markup RenderingEPSS 0.7%CVE-2021-47936CRITICALOpenCATS 0.9.4 Remote Code Execution via Resume UploadEPSS 0.7%