Fallos del tipo CWE-306

2619 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-55884CRITICALTilt: Missing authentication on the network-exposed Tilt HUD serverEPSS 0.5%CVE-2022-50591HIGHAdvantech iView < v5.7.04 Build 6425 ztp_config_id Parameter SQL Injection Information DisclosureEPSS 0.5%CVE-2023-34761—An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypassEPSS 0.5%CVE-2026-63647CRITICALCordysCRM SSE Notification Stream Hijack via `/sse/subscribe`EPSS 0.5%CVE-2026-28450HIGHOpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP EndpointsEPSS 0.5%CVE-2026-92717CRITICALCovenant through 0.6 Missing Authentication on the CovenantHub SignalR HubEPSS 0.5%CVE-2026-34758CRITICALOneUptime: Missing Authentication on Notification EndpointsEPSS 0.5%CVE-2026-25791HIGHSliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of ServiceEPSS 0.5%CVE-2026-47040CRITICALVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.EPSS 0.5%CVE-2026-33719HIGHAVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.phpEPSS 0.5%CVE-2026-46910CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). SupportedEPSS 0.5%CVE-2026-61155CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2022-0878MEDIUMNovel attack against the Combined Charging System (CCS) in electric vehicles to remotely cause a denial of serviceEPSS 0.5%CVE-2026-61130CRITICALVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version EPSS 0.5%CVE-2026-25878MEDIUMFroshAdminer Adminer UI is accessible without admin sessionEPSS 0.5%CVE-2026-1632CRITICALRISS SRL MOMA Seismic Station Missing Authentication for Critical FunctionEPSS 0.5%CVE-2025-41715CRITICALMissing Authentication for Database Access in Web ApplicationEPSS 0.5%CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%CVE-2024-48791HIGHAn issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware EPSS 0.5%CVE-2026-72871HIGHDokploy: Unauthenticated Git Provider Injection via GitHub OAuth CallbackEPSS 0.5%