Fallos del tipo CWE-306

2612 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-22101HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2023-53967CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password ChangeEPSS 0.5%CVE-2026-86801HIGHTo Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload HandlerEPSS 0.5%CVE-2026-58473CRITICALCognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settingsEPSS 0.5%CVE-2018-25136HIGHFLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2025-15620CRITICALHiOS Switch Platform Denial-of-Service via Web InterfaceEPSS 0.5%CVE-2024-54983CRITICALAn issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.EPSS 0.5%CVE-2026-26319HIGHOpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated RequestsEPSS 0.5%CVE-2024-54984CRITICALAn issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the EPSS 0.5%CVE-2026-88285CRITICALGV-LPC2011/LPC2211 - Unauthenticated PTZ Control ServiceEPSS 0.5%CVE-2024-45229MEDIUMThe Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, andEPSS 0.5%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.5%CVE-2025-27935HIGHAuthentication Bypass in OTP (One-time Passcode) IdP Adapter Integration KitEPSS 0.5%CVE-2020-7479—A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), EPSS 0.5%CVE-2026-88065HIGH`tts-be` application has a Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-53469CRITICALMigration-planner: unprotected delete endpoint wipes all tenant dataEPSS 0.5%CVE-2026-61233CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported EPSS 0.5%CVE-2026-60240CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60253CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-60329CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are afEPSS 0.5%