Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-15706CRITICALMissing Authentication for Critical Function in Management API in Baylan Water Meters's BMSEPSS 0.6%CVE-2022-34908HIGHAn issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some fEPSS 0.6%CVE-2026-21446HIGHBagisto Missing Authentication on Installer API EndpointsEPSS 0.6%CVE-2026-6274CRITICALAuthentication Bypass in DTS Electronics' Redline WR3200EPSS 0.6%CVE-2026-47396CRITICALPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unsetEPSS 0.6%CVE-2026-57140CRITICALPraisonAI AgentOS exposes unauthenticated agent listing and invocationEPSS 0.6%CVE-2026-92805CRITICALUVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation WizardEPSS 0.6%CVE-2026-41930CRITICALVvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdminEPSS 0.6%CVE-2026-2754HIGHNavtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated rEPSS 0.6%CVE-2026-62327CRITICAL9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/statsEPSS 0.6%CVE-2026-82473HIGHKubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task EndpointsEPSS 0.6%CVE-2026-25116HIGHRuntipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path TraversalEPSS 0.6%CVE-2018-25134CRITICALSynaccess netBooter NP-02x/NP-08x 6.8 Authentication Bypass via webNewAcct.cgiEPSS 0.6%CVE-2025-57432CRITICALBlackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remoteEPSS 0.6%CVE-2024-8053HIGHImproper Authentication in open-webui/open-webuiEPSS 0.6%CVE-2024-4332CRITICALImproper Authentication in Tripwire Enterprise 9.1.0 APIsEPSS 0.6%CVE-2024-3701CRITICALImproper Authentication in com.transsion.kolun.aiserviceEPSS 0.6%CVE-2023-53968CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase AccountEPSS 0.6%CVE-2026-27595CRITICALParse Dashboard has incomplete authentication on AI Agent endpointEPSS 0.6%CVE-2026-34741HIGHCombodo iTop: Authentication bypass in exec.php allows PHP file executionEPSS 0.6%