Fallos del tipo CWE-306

2610 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-11661MEDIUMProjectsAndPrograms School Management System missing authenticationEPSS 0.5%CVE-2026-22096CRITICALMissing authentication for webserver endpointsEPSS 0.5%CVE-2026-44895CRITICALGitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab toolsEPSS 0.5%CVE-2025-8284CRITICALPacket Power EMX and EG Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-1453CRITICALMissing Authentication for Critical Function in KiloView Encoder SeriesEPSS 0.5%CVE-2026-2065MEDIUMFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authenticationEPSS 0.5%CVE-2026-54309HIGHn8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control SessionsEPSS 0.5%CVE-2022-41776HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration methoEPSS 0.5%CVE-2023-41367MEDIUMMissing Authentication check in SAP NetWeaver (Guided Procedures)EPSS 0.5%CVE-2026-50287HIGHMissing Authentication for Critical Function in @agenticmail/mcpEPSS 0.5%CVE-2026-12819CRITICALDVP-12SE Missing Authentication and Unauthorized Write access VulnerabilityEPSS 0.5%CVE-2026-42856HIGHNetwork-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool callsEPSS 0.5%CVE-2026-90449MEDIUMWhen a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface EPSS 0.5%CVE-2026-45044HIGHRustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlersEPSS 0.5%CVE-2026-47136MEDIUMRustFS: Unauthenticated RustFS console license endpoint exposes license metadataEPSS 0.5%CVE-2025-63958CRITICALMILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authEPSS 0.5%CVE-2026-73673HIGHNetis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware AuthenticationEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.5%CVE-2026-9152CRITICALUnauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index DestructionEPSS 0.5%CVE-2024-41793HIGHA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an enEPSS 0.5%