Fallos del tipo CWE-306

2619 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-83283CRITICALVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The suppoEPSS 0.5%CVE-2026-82995CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-25192CRITICALCTEK Chargeportal Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-83021CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affEPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%CVE-2026-80462CRITICALPrivilege Escalation in Progress Chef AutomateEPSS 0.5%CVE-2026-83232CRITICALVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versiEPSS 0.5%CVE-2026-83000CRITICALVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.5%CVE-2026-83452CRITICALVulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). SuppEPSS 0.5%CVE-2026-73961CRITICALVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.5%CVE-2026-40461HIGHAnviz Products Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-73843CRITICALOpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsEPSS 0.5%CVE-2024-39300HIGHMissing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is eEPSS 0.5%CVE-2026-67610HIGHOpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR AccessEPSS 0.5%CVE-2025-48469CRITICALUnauthenticated Firmware UploadEPSS 0.5%CVE-2026-49254LOWDragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauthEPSS 0.5%CVE-2024-21654MEDIUMrubygems.org MFA Bypass through password reset function could allow account takeover EPSS 0.5%CVE-2017-20213HIGHFLIR Thermal Camera F/FC/PT/D Stream 8.0.0.64 Unauthenticated Stream DisclosureEPSS 0.5%CVE-2025-6260CRITICALNetwork Thermostat X-Series WiFi Thermostats Missing Authentication for Critical FunctionEPSS 0.5%CVE-2026-53981HIGHCap-go < v12.128.2 Account Takeover via Unauthenticated Email Change MechanismEPSS 0.5%