Fallos del tipo CWE-306

2613 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-27261MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%CVE-2025-9994CRITICALAmp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not require authenticationEPSS 0.5%CVE-2026-14446CRITICALIBM WebSphere Application Server is affected by a privilege escalationEPSS 0.5%CVE-2026-14529CRITICALIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgeryEPSS 0.5%CVE-2026-1341CRITICALMissing Authentication for Critical Function in Avation Light Engine ProEPSS 0.5%CVE-2026-30933HIGHFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/infoEPSS 0.5%CVE-2024-39601HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1EPSS 0.5%CVE-2024-12757HIGHNedap Librix Ecoreader Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-23944HIGHArcane allows unauthenticated proxy access to remote environmentsEPSS 0.5%CVE-2026-48814CRITICALNetwork-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)EPSS 0.5%CVE-2026-40289CRITICALPraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessionsEPSS 0.5%CVE-2020-22661MEDIUMIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.5%CVE-2026-33038HIGHAVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deploymentsEPSS 0.5%CVE-2026-63101HIGHOpen Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export EndpointEPSS 0.5%CVE-2026-75133HIGHKeep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_processEPSS 0.5%CVE-2026-3323HIGHVEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devicesEPSS 0.5%CVE-2026-88259HIGHCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-23783HIGHImproper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows aEPSS 0.5%CVE-2025-8861CRITICALChanging|TSA - Missing AuthenticationEPSS 0.5%CVE-2025-34222CRITICALVasion Print (formerly PrinterLogic) Unauthenticated Admin APIs Used to Modify SSL CertificatesEPSS 0.5%