Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2022-25247CRITICALPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 4.1%CVE-2022-26501CRITICALVeeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).EPSS 4.1%KEVCVE-2024-3661HIGHDHCP routing options can manipulate interface-based VPN trafficEPSS 4.1%CVE-2026-26190CRITICALMilvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System CompromiseEPSS 4.0%CVE-2018-1164—This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router EPSS 4.0%CVE-2021-42783—Missing Authentication in debug_post_set.cgi in D-Link DWR-932C E1 Firmware 1.0.0.4EPSS 3.9%CVE-2026-42796CRITICALArelle < 2.39.10 Unauthenticated RCE via /rest/configureEPSS 3.9%CVE-2026-41452CRITICALKrayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setupEPSS 3.7%CVE-2013-10032HIGHGetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File UploadEPSS 3.7%CVE-2026-73296CRITICALMicrosoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosureEPSS 3.7%CVE-2026-36356CRITICALThe GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injecEPSS 3.6%CVE-2026-56782CRITICALGorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore EndpointsEPSS 3.6%CVE-2025-34115HIGHOP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpEPSS 3.6%CVE-2021-20990HIGHFibaro Home Center Unauthenticated access to shutdown, reboot and reboot to recovery modeEPSS 3.4%CVE-2018-10603—Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commEPSS 3.4%CVE-2026-46339CRITICAL9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routesEPSS 3.4%CVE-2025-34100CRITICALBuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File UploadEPSS 3.3%CVE-2018-4834CRITICALA vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), EPSS 3.3%CVE-2016-6544—iTrack Easy's getgps data can be modified without authenticationEPSS 3.3%CVE-2026-41176CRITICALRclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionEPSS 3.2%