Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2020-36874HIGHACE SECURITY WIP-90113 Unauthenticated Configuration DisclosureEPSS 0.7%CVE-2026-6577MEDIUMliangliangyy DjangoBlog logtracks Endpoint views.py missing authenticationEPSS 0.7%CVE-2026-90579MEDIUMcheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authenticationEPSS 0.7%CVE-2026-90504MEDIUMvvbbnn00 WARP-Clash-API authorized missing authenticationEPSS 0.7%CVE-2026-15491MEDIUMRafyMrX TOKO-ONLINE-ROTI missing authenticationEPSS 0.7%CVE-2026-82919MEDIUMcu silicon edit Endpoint views.py create_app missing authenticationEPSS 0.7%CVE-2026-5632MEDIUMassafelovic gpt-researcher HTTP REST API Endpoint missing authenticationEPSS 0.7%CVE-2026-5000MEDIUMPromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authenticationEPSS 0.7%CVE-2026-18810MEDIUMH3C NX15 networkSetup missing authenticationEPSS 0.7%CVE-2026-13546MEDIUMFeehi CMS REST API Endpoint articles missing authenticationEPSS 0.7%CVE-2026-7042MEDIUM666ghj MiroFish REST API Endpoint __init__.py create_app missing authenticationEPSS 0.7%CVE-2026-6129MEDIUMzhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authenticationEPSS 0.7%CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-93559MEDIUMForget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authenticationEPSS 0.7%CVE-2026-5320MEDIUMvanna-ai vanna Chat API Endpoint v2 missing authenticationEPSS 0.7%CVE-2026-4562MEDIUMMacCMS Timming API Endpoint Timming.php weak authenticationEPSS 0.7%CVE-2026-6582MEDIUMTransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authenticationEPSS 0.7%CVE-2026-45083CRITICALGoobi viewer: Unauthenticated Solr Streaming Expression ProxyEPSS 0.7%CVE-2022-29877—A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.0EPSS 0.7%CVE-2026-4640HIGHGalaxy Software Services|Vitals ESP - Missing AuthenticationEPSS 0.7%