Fallos del tipo CWE-306

2622 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-34434CRITICALAVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and DeletionEPSS 0.5%CVE-2026-60439HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60373HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2019-25686HIGHCore FTP 2.0 build 653 PBSZ Unauthenticated Denial of ServiceEPSS 0.5%CVE-2026-77097HIGHPrivate Metrics Server Denial of ServiceEPSS 0.5%CVE-2026-2234CRITICALHGiga|C&Cm@il - Missing AuthenticationEPSS 0.5%CVE-2023-37495MEDIUMHCL Domino is susceptible to a weak cryptography vulnerabilityEPSS 0.5%CVE-2026-75479HIGHJimuReport Unauthenticated Report Listing and Share Token DisclosureEPSS 0.5%CVE-2025-32377MEDIUMRasa Pro Missing Authentication For Voice Connector APIsEPSS 0.5%CVE-2024-8419HIGHImproper Access Control vulnerability in AC4xxS devicesEPSS 0.5%CVE-2026-83327CRITICALVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2026-86681HIGHBroken Access Control vulnerabilityEPSS 0.5%CVE-2026-74243MEDIUMQuay: unauthenticated secscan notification endpoint in quay when psk is unsetEPSS 0.5%CVE-2026-70861HIGHVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supportEPSS 0.5%CVE-2022-43554HIGHIvanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-44847HIGHMaxKB: Webhook Trigger Authentication BypassEPSS 0.5%CVE-2023-33247HIGHTalend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be EPSS 0.5%CVE-2026-1332MEDIUMHAMASTAR Technology|MeetingHub - Missing AuthenticationEPSS 0.5%CVE-2022-43555HIGHIvanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2024-11980HIGHBillion Electric router - Missing AuthenticationEPSS 0.5%