Fallos del tipo CWE-306

2622 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2019-25240HIGHRifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticated Live Stream Disclosure via animate.cgiEPSS 0.5%CVE-2026-56321MEDIUMCapgo - Missing Authentication Middleware on GET /private/role_bindings EndpointEPSS 0.5%CVE-2025-7405HIGHInformation Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU moduleEPSS 0.5%CVE-2023-54342CRITICALEclipse Equinox OSGi 3.8-3.18 Console Remote Code ExecutionEPSS 0.5%CVE-2026-61203CRITICALVulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is EPSS 0.5%CVE-2026-65311MEDIUMMissing authentication for logging-configuration endpointEPSS 0.5%CVE-2026-93964MEDIUMNginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authenticationEPSS 0.5%CVE-2026-100903MEDIUMООО НПО Ритм GEOritm REST API obj-groups missing authenticationEPSS 0.5%CVE-2026-15576MEDIUMAgent receiver accepts mTLS requests without a client certificateEPSS 0.5%CVE-2026-55534HIGHPraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executionEPSS 0.5%CVE-2023-34392HIGHMissing Authentication for Critical FunctionEPSS 0.5%CVE-2019-25236HIGHiSeeQ Hybrid DVR WH-H4 1.03R Unauthenticated Live Stream DisclosureEPSS 0.5%CVE-2024-40405HIGHIncorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker viaEPSS 0.5%CVE-2026-89263MEDIUMMoguBlog through 6.2 Missing Authentication on the Comment Email-Notification EndpointEPSS 0.5%CVE-2023-24527MEDIUMImproper Access Control in SAP NetWeaver AS Java for Deploy ServiceEPSS 0.5%CVE-2025-3090HIGHMB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24EPSS 0.5%CVE-2023-0116HIGHThe reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect avaiEPSS 0.5%CVE-2025-61777CRITICALFlagForge Allows Unauthenticated Badge Template API AccessEPSS 0.5%CVE-2023-5253MEDIUMCheck Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0EPSS 0.5%CVE-2021-36780HIGHUnauthorized data access from replicas through vulnerable instance manager podsEPSS 0.5%