Fallos del tipo CWE-306

2609 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-34200HIGHNhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network PortEPSS 0.6%CVE-2026-51937HIGHAn issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.javEPSS 0.6%CVE-2026-73246HIGHKestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentialsEPSS 0.6%CVE-2021-4461CRITICALSeeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication BypassEPSS 0.6%CVE-2026-82641HIGHKeploy 3.1.0-3.6.25 Unauthenticated TLS Key ExposureEPSS 0.6%CVE-2026-67966CRITICALTenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shEPSS 0.6%CVE-2024-1573MEDIUMMissing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.EPSS 0.6%CVE-2023-2187MEDIUMOn Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WeEPSS 0.6%CVE-2023-49115HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-38059HIGHST Engineering iDirect iQ-Series Terminals Missing authentication for critical functionEPSS 0.6%CVE-2026-2165MEDIUMdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authenticationEPSS 0.6%CVE-2025-30215CRITICALNATS-Server Fails to Authorize Certain Jetstream Admin APIsEPSS 0.6%CVE-2023-22803HIGHCVE-2023-22803EPSS 0.6%CVE-2025-8558LOWInsider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated uEPSS 0.6%CVE-2024-32752HIGHJohnson Controls Software House iSTAR Configuration Utility (ICU) ToolEPSS 0.6%CVE-2024-41988CRITICALMissing Authentication for Critical Function vulnerability in TEM Opera Plus FM Family TransmitterEPSS 0.6%CVE-2026-65014MEDIUMn8n before 2.28.0 Authentication Bypass via test-webhookEPSS 0.6%CVE-2026-62325CRITICALgoshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)EPSS 0.6%CVE-2026-59808HIGHAVideo Authentication Bypass via Unkeyed Video Hash DisclosureEPSS 0.6%CVE-2026-84075CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%