Fallos del tipo CWE-306

2623 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-48774HIGHAn issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware updatEPSS 0.4%CVE-2024-21183HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-31983MEDIUMMissing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0EPSS 0.4%CVE-2026-65012MEDIUMInvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderEPSS 0.4%CVE-2020-37146HIGHAptina AR0130 960P 1.3MP Camera - Remote Configuration DisclosureEPSS 0.4%CVE-2024-7015HIGHImproper Authentication in Profelis Informatics and Consulting's PassBOXEPSS 0.4%CVE-2026-82282HIGHAtlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated CallersEPSS 0.4%CVE-2026-12722HIGHAuthentication Bypass in FTC Software's E-Commerce Management PanelEPSS 0.4%CVE-2026-80208HIGHAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Account Closure EndpointsEPSS 0.4%CVE-2023-39436MEDIUMInformation Disclosure in SAP Supplier Relationship ManagementEPSS 0.4%CVE-2026-22207CRITICALOpenViking Missing root_api_key Allows Anonymous ROOT AccessEPSS 0.4%CVE-2024-33622MEDIUMMissing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerabilitEPSS 0.4%CVE-2025-40736CRITICALA vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorEPSS 0.4%CVE-2026-28458HIGHOpenClaw 2026.1.20 < 2026.2.1 - Missing Authentication in Browser Relay /cdp WebSocket EndpointEPSS 0.4%CVE-2026-101065CRITICALObot Quickstart Docker Deployment Unauthenticated Admin AccessEPSS 0.4%CVE-2023-27983MEDIUMA CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of rEPSS 0.4%CVE-2026-5029HIGHRCE in Code Runner MCP ServerEPSS 0.4%CVE-2026-27471CRITICALERP: Document access through endpoints due to missing validationEPSS 0.4%CVE-2026-50225HIGHAccount Creation ExhaustionEPSS 0.4%CVE-2025-65731MEDIUMAn issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical acceEPSS 0.4%