Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2022-26082CRITICALA file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. EPSS 20.1%CVE-2024-10386CRITICALRockwell Automation FactoryTalk ThinManager Authentication VulnerabilityEPSS 19.3%CVE-2025-58443CRITICALFOG's authentication bypass leads to full SQL DB dumpEPSS 18.5%CVE-2019-5591MEDIUMA Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive informationEPSS 18.4%KEVCVE-2022-45504HIGHAn issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to EPSS 18.3%CVE-2025-61928CRITICALBetter Auth: Unauthenticated API key creation through api-key pluginEPSS 17.9%CVE-2010-5326CRITICALThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows rEPSS 17.8%KEVCVE-2019-6543—AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20EPSS 17.3%CVE-2026-22812HIGHOpenCode's Unauthenticated HTTP Server Allows Arbitrary Command ExecutionEPSS 16.8%CVE-2026-59726CRITICALRuflo: Unauthenticated RCE in MCP bridge default docker-compose deploymentEPSS 16.4%CVE-2020-27986HIGHSonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE:EPSS 16.0%CVE-2021-28809CRITICALMissing Authentication for Critical Function in RTRR Server in HBS3EPSS 15.8%CVE-2024-42455HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserializatEPSS 15.2%CVE-2025-34077CRITICALWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCEEPSS 15.1%CVE-2023-27267CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge)EPSS 14.2%CVE-2025-41656CRITICALPilz: Missing Authentication in Node-RED integrationEPSS 13.8%CVE-2023-41183HIGHNETGEAR Orbi 760 SOAP API Authentication Bypass VulnerabilityEPSS 13.6%CVE-2020-12004—The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and IgnitEPSS 13.6%CVE-2026-36356CRITICALThe GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injecEPSS 13.5%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEV