Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2021-4468HIGHPLANEX CS-QP50F-ING2 Smart Camera Remote Configuration DisclosureEPSS 0.7%CVE-2026-31071CRITICALAPI endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers caEPSS 0.7%CVE-2024-21007HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.7%CVE-2024-3279CRITICALImproper Access Control in mintplex-labs/anything-llmEPSS 0.6%CVE-2020-36871HIGHESCAM QD-900 Unauthenticated Configuration DisclosureEPSS 0.6%CVE-2025-53378HIGHA missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticaEPSS 0.6%CVE-2025-12003HIGHA path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of thEPSS 0.6%CVE-2025-9254CRITICALUniong|WebITR - Missing AuthenticationEPSS 0.6%CVE-2026-62645CRITICALA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be usEPSS 0.6%CVE-2025-8610CRITICALAOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-40702CRITICALEVoke Systems EVoke CSMS Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-97879MEDIUMzhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authenticationEPSS 0.6%CVE-2025-8611CRITICALAOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-53072CRITICALVulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that areEPSS 0.6%CVE-2026-40884CRITICALgoshs: Empty-username SFTP password authentication bypass in goshsEPSS 0.6%CVE-2026-27012CRITICALUnauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.phpEPSS 0.6%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.6%CVE-2025-10452CRITICALGotac|Statistical Database System - Missing AuthenticationEPSS 0.6%CVE-2022-34908HIGHAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some fEPSS 0.6%CVE-2026-21446HIGHBagisto Missing Authentication on Installer API EndpointsEPSS 0.6%