Fallos del tipo CWE-306

2619 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-60385CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-60291CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-60290CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.5%CVE-2026-61233CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported EPSS 0.5%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.5%CVE-2024-27758HIGHIn RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(cEPSS 0.5%CVE-2026-67426CRITICALFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationEPSS 0.5%CVE-2026-63429HIGHHeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextEPSS 0.5%CVE-2023-4884MEDIUMMultiple vulnerabilities in Open5GSEPSS 0.5%CVE-2026-65319HIGHFeedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/textEPSS 0.5%CVE-2026-27449HIGHUmbraco.Engage.Forms Allows Unauthorized Access to Multiple API EndpointsEPSS 0.5%CVE-2026-55571HIGHdjust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler callsEPSS 0.5%CVE-2022-32503HIGHAn issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect toEPSS 0.5%CVE-2026-15978HIGHCVE-2026-15978EPSS 0.5%CVE-2026-89250HIGHWWBN AVideo Unauthenticated File Read via getRecordedFile.phpEPSS 0.5%CVE-2025-25060HIGHMissing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server whEPSS 0.5%CVE-2026-80234MEDIUMCAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing AuthenticationEPSS 0.5%CVE-2024-10776HIGHSICK InspectorP61x and SICK InspectorP62x: missing authenticationEPSS 0.5%CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2026-9202CRITICALUnauthenticated User Registration Could Lead to Remote Code ExecutionEPSS 0.5%