Fallos del tipo CWE-306

2623 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-70559HIGHDinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAllEPSS 0.5%CVE-2026-53868HIGHCapgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and DeletionEPSS 0.5%CVE-2026-42864CRITICALFireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theftEPSS 0.4%CVE-2026-20343HIGHCisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service VulnerabilityEPSS 0.4%CVE-2024-43798HIGHChisel AUTH environment variable not respected in server entrypointEPSS 0.4%CVE-2026-34411MEDIUMAppsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIsEPSS 0.4%CVE-2024-48773HIGHAn issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update processEPSS 0.4%CVE-2024-48777HIGHLEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.EPSS 0.4%CVE-2026-63098MEDIUMTheHive 4.1.24 Unauthenticated Information Disclosure via /api/status EndpointEPSS 0.4%CVE-2024-48776HIGHAn issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update processEPSS 0.4%CVE-2024-48775HIGHAn issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update procEPSS 0.4%CVE-2026-100672HIGHgrav-plugin-comments before 1.2.11 Unauthenticated Information DisclosureEPSS 0.4%CVE-2026-82265MEDIUMZipkin Unauthenticated Spring Boot Actuator Endpoints ExposureEPSS 0.4%CVE-2025-11949HIGHDigiwin|EasyFlow .NET and EasyFlow AiNet - Missing AuthenticationEPSS 0.4%CVE-2026-24068HIGHMissing XPC Client & NSXPC endpoint validation leads to privilege escalation in Vienna Assistant (MacOS) - Vienna Symphonic LibraryEPSS 0.4%CVE-2026-55538HIGHPraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticatedEPSS 0.4%CVE-2026-60591CRITICALVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2023-45851HIGHThe Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  EPSS 0.4%CVE-2026-70979CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-33543CRITICALFOSSBilling: Authentication bypass allows unauthenticated administrator creationEPSS 0.4%