Fallos del tipo CWE-306

2608 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-20357CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.6%CVE-2026-56346MEDIUMAVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php EndpointEPSS 0.6%CVE-2023-54352CRITICALWordPress Seotheme Remote Code Execution UnauthenticatedEPSS 0.6%CVE-2026-14976HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerabilityEPSS 0.6%CVE-2026-69091HIGHAdmidio before 5.0.11 Authentication Bypass via forum.phpEPSS 0.6%CVE-2026-84485HIGHAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search EndpointEPSS 0.6%CVE-2026-62422CRITICALIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass vEPSS 0.6%CVE-2026-50242CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via diEPSS 0.6%CVE-2026-13007HIGHInsecure Public Caching on REST API Endpoints in Tenable Identity ExposureEPSS 0.6%CVE-2026-72688HIGHOpenSignLabs opensignserver - Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-77254CRITICALMCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentialsEPSS 0.6%CVE-2026-81094CRITICALmcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring AuthenticationEPSS 0.6%CVE-2023-22650HIGHRancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderEPSS 0.6%CVE-2026-4767CRITICALImproper Access Control in TR7's WAF-ASPEPSS 0.6%CVE-2026-44321HIGHfree5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)EPSS 0.6%CVE-2022-35136MEDIUMBoodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.EPSS 0.6%CVE-2026-75329CRITICALThe Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can dirEPSS 0.6%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.6%CVE-2025-5906MEDIUMcode-projects Laundry System data missing authenticationEPSS 0.6%CVE-2023-5881HIGHUnauthenticated access permitted to web interface page "Garage Door Control Module Setup"EPSS 0.6%