Fallos del tipo CWE-306

2609 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-84075CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2021-47933CRITICALWordPress MStore API 2.0.6 Arbitrary File UploadEPSS 0.6%CVE-2024-6422CRITICALPepperl+Fuchs: OIT Products can be manipulated via unintended Telnet accessEPSS 0.6%CVE-2024-6981CRITICALOMNTEC Proteus Tank Monitoring Missing Authentication for Critical FunctionEPSS 0.6%CVE-2022-41271CRITICALAn unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PEPSS 0.6%CVE-2026-32064HIGHOpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC ObserverEPSS 0.6%CVE-2026-69703CRITICALAtlas-Livre Unauthenticated Access via Admin Controllers Missing ExitEPSS 0.6%CVE-2026-88263HIGHXikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration datEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.6%CVE-2026-34731HIGHAVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.phpEPSS 0.6%CVE-2026-92729HIGHSigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics EndpointsEPSS 0.6%CVE-2025-11852MEDIUMApeman ID71 ONVIF Service device_service missing authenticationEPSS 0.6%CVE-2022-20861CRITICALCisco Nexus Dashboard Unauthorized Access VulnerabilitiesEPSS 0.6%CVE-2023-6221HIGHMachineSense FeverWarn Missing Authentication for Critical FunctionEPSS 0.6%CVE-2026-25848CRITICALIn JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possibleEPSS 0.6%CVE-2026-54061CRITICALDgraph Alpha group stores can be replaced via unauthenticated external snapshot importEPSS 0.6%CVE-2026-8602HIGHMissing authentication for critical function in ScadaBREPSS 0.6%CVE-2020-5589—SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SPEPSS 0.6%CVE-2026-84700HIGHPika Unauthenticated Replication Access via Internal Protobuf PortEPSS 0.6%