Fallos del tipo CWE-306

2619 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2026-9202CRITICALUnauthenticated User Registration Could Lead to Remote Code ExecutionEPSS 0.5%CVE-2024-9137HIGHMoxa Service Missing Authentication for Critical FunctionEPSS 0.5%CVE-2023-25013HIGHAn issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in EPSS 0.5%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.5%CVE-2024-3281HIGHA vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build EPSS 0.5%CVE-2026-65310HIGHMissing authentication and permissive CORS policyEPSS 0.5%CVE-2026-76355HIGHUnauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk EnterpriseEPSS 0.5%CVE-2026-44100HIGHJupiCore charging point reconfiguration without authEPSS 0.5%CVE-2018-25137HIGHFLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated Config File DisclosureEPSS 0.5%CVE-2024-41969HIGHWAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesEPSS 0.5%CVE-2026-16527HIGHPcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rulesEPSS 0.5%CVE-2026-86480CRITICALIn JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privilegesEPSS 0.5%CVE-2024-52438HIGHWordPress de:branding plugin <= 1.0.2 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-100746MEDIUMcoollabsio Coolify GitHub App Setup redirect missing authenticationEPSS 0.5%CVE-2025-2567CRITICALLantronix Xport Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-52437HIGHWordPress Banner System plugin <= 1.0.0 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-4649MEDIUMAuth bypass in Apache Artemis allows reading all internal messagesEPSS 0.5%CVE-2026-67349HIGHOpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin BypassEPSS 0.5%CVE-2026-91996HIGHlamp-cloud through 5.10.0 Missing Authentication for JVM Properties EndpointEPSS 0.5%