Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-5716CRITICALASUS Armoury Crate - Arbitrary File WriteEPSS 0.6%CVE-2023-38422HIGHWalchem Intuition Missing Authentication for Critical Function EPSS 0.6%CVE-2023-21979HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.6%CVE-2026-58375HIGHJimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/exportEPSS 0.6%CVE-2026-72586HIGHfrangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event HandlerEPSS 0.6%CVE-2026-35064HIGHSenseLive X3050 Missing authentication for critical functionEPSS 0.6%CVE-2026-92720CRITICALKubero through 3.1.1 Unauthenticated Notifications API AccessEPSS 0.6%CVE-2026-85701MEDIUMramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authenticationEPSS 0.6%CVE-2026-28472CRITICALOpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect HandshakeEPSS 0.6%CVE-2022-50595CRITICALAdvantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCEEPSS 0.6%CVE-2022-50592CRITICALAdvantech iView < v5.7.04 Build 6425 getInventoryReportData Parameter SQL Injection RCEEPSS 0.6%CVE-2026-14162CRITICALAdvantech|Hospital Quering Management - Missing AuthenticationEPSS 0.6%CVE-2026-71262CRITICALIoTSharp BlobStorageController Missing Authentication and Path TraversalEPSS 0.6%CVE-2023-28470MEDIUMIn Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.EPSS 0.6%CVE-2026-10243MEDIUMcode-projects Smart Parking System Admin Endpoint missing authenticationEPSS 0.6%CVE-2025-58083CRITICALGeneral Industrial Controls Lynx+ Gateway Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-71319CRITICALNuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionEPSS 0.6%CVE-2022-41629HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, whichEPSS 0.6%CVE-2021-4469HIGHDenver SHO-110 IP Camera Unauthenticated Snapshot AccessEPSS 0.6%CVE-2026-19749MEDIUMTenda CH7 RTSP/ONVIF missing authenticationEPSS 0.6%