Fallos del tipo CWE-306

2619 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2022-23862HIGHA Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMEPSS 0.5%CVE-2026-71241HIGHBook-Management-System - Unauthenticated Disclosure of Student PII and Borrowing HistoryEPSS 0.5%CVE-2026-61594CRITICALdjust has an authorization bypass on the WebSocket/SSE mount pathEPSS 0.5%CVE-2023-0919HIGHMissing Authentication for Critical Function in kareadita/kavitaEPSS 0.5%CVE-2025-65112CRITICALPubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity SpoofingEPSS 0.5%CVE-2026-69228MEDIUMmissing authentication vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2020-36904CRITICALSelea CarPlateServer 4.0.1.6 Remote Program Execution via Configuration EndpointEPSS 0.5%CVE-2026-71214CRITICALNASA-AMMOS plandev - Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-serverEPSS 0.5%CVE-2025-10204HIGHUnauth Admin Reset Password on AC Smart IIEPSS 0.5%CVE-2026-83151CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%CVE-2026-70748CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2026-83283CRITICALVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The suppoEPSS 0.5%CVE-2026-82994CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-83452CRITICALVulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). SuppEPSS 0.5%CVE-2026-80462CRITICALPrivilege Escalation in Progress Chef AutomateEPSS 0.5%CVE-2026-73961CRITICALVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.5%CVE-2026-25192CRITICALCTEK Chargeportal Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-83232CRITICALVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versiEPSS 0.5%CVE-2026-82995CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%