Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-97878MEDIUMzhistaredu StarTraining Druid Console index.html anonymous missing authenticationEPSS 0.6%CVE-2025-53938MEDIUMWeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpointsEPSS 0.6%CVE-2024-45276HIGHMB connect line/Helmholz: tmp directory exposed via webserviceEPSS 0.6%CVE-2025-13510CRITICALIskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiyEPSS 0.6%CVE-2021-32709MEDIUMCreation of order credits was not validated by acl in admin ordersEPSS 0.6%CVE-2023-22072CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected EPSS 0.6%CVE-2022-3738MEDIUMWAGO: Missing authentication for config export functionality in multiple productsEPSS 0.6%CVE-2024-35293CRITICALSchneider Elektronik Series 700 prone to missing authentication for critical reset functionEPSS 0.6%CVE-2026-58574CRITICALDell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to thEPSS 0.6%CVE-2022-45433LOWSome Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall acEPSS 0.6%CVE-2023-30744HIGHImproper access control during application start-up in SAP AS NetWeaver JAVA.EPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2024-12511HIGHSMB/FTP Address Book Scan Pass-back attackEPSS 0.6%CVE-2026-45327HIGHTinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injectionEPSS 0.6%CVE-2026-50085HIGHAqara Board IoT insecure debug APIEPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%CVE-2026-82266CRITICALRedpanda Admin API Unauthenticated Superuser Access via Default ConfigurationEPSS 0.6%CVE-2026-34162CRITICALFastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key TheftEPSS 0.6%CVE-2026-54446HIGHNetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP ModeEPSS 0.6%CVE-2024-45049HIGHNix Hydra Missing authentication when triggering evaluationsEPSS 0.6%