Fallos del tipo CWE-306

2622 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-5872MEDIUMeGauge EG3000 Energy Monitor Setting missing authenticationEPSS 0.5%CVE-2025-5876MEDIUMLucky LM-520-SC/LM-520-FSC/LM-520-FSC-SAM missing authenticationEPSS 0.5%CVE-2026-84831HIGHMandatory MFA bypass before enrollmentEPSS 0.5%CVE-2026-32957MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenEPSS 0.5%CVE-2025-41655HIGHPEPPERL+FUCHS: Attacker can cause a DoS via URLEPSS 0.5%CVE-2026-84078CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-83197CRITICALVulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions thatEPSS 0.5%CVE-2026-32962MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuEPSS 0.5%CVE-2026-32594MEDIUMParse Server GraphQL WebSocket endpoint bypasses security middlewareEPSS 0.5%CVE-2018-25141HIGHFLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2022-50977HIGHMultiple Innomic VibroLine VLX and avibia AVLX allow unauthenticated configuration preset change via HTTPEPSS 0.5%CVE-2026-34227MEDIUMSliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP InterfaceEPSS 0.5%CVE-2019-25248HIGHBeward N100 M2.1.6 Unauthenticated RTSP Video Stream DisclosureEPSS 0.5%CVE-2026-79687CRITICALDell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access EPSS 0.5%CVE-2026-92972HIGHSGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpointEPSS 0.5%CVE-2025-53037CRITICALVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.5%CVE-2026-80132HIGHell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticatEPSS 0.5%CVE-2026-47769MEDIUMAPIFold Vulnerable to Unauthenticated Webhook Event InjectionEPSS 0.5%CVE-2024-21846MEDIUMElectrolink FM/DAB/TV Transmitter Missing Authentication for Critical FunctionEPSS 0.5%CVE-2019-25686HIGHCore FTP 2.0 build 653 PBSZ Unauthenticated Denial of ServiceEPSS 0.5%