Fallos del tipo CWE-306

2623 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-57476MEDIUMDeloitte AI Assist for Customer unauthenticated RAG corpus read and writeEPSS 0.4%CVE-2025-65731MEDIUMAn issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical acceEPSS 0.4%CVE-2026-0647HIGHRockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple VulnerabilitiesEPSS 0.4%CVE-2026-68929CRITICALFastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorizationEPSS 0.4%CVE-2026-61176MEDIUMVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2026-44775MEDIUMKavita: No authentication at /api/Reader/imageEPSS 0.4%CVE-2024-30391MEDIUMJunos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performedEPSS 0.4%CVE-2026-33159MEDIUMCraft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted usersEPSS 0.4%CVE-2026-9142CRITICALInsecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not presentEPSS 0.4%CVE-2026-45248MEDIUMHedera Guardian Authentication Bypass Information DisclosureEPSS 0.4%CVE-2026-79668MEDIUMEch0 before 4.7.3 Unauthenticated Like Endpoint Metric InflationEPSS 0.4%CVE-2023-40585HIGHUnauthenticated access to Ironic APIEPSS 0.4%CVE-2016-15045HIGHDeepin lastore-daemon Privilege Escalation via Unsigned .deb InstallationEPSS 0.4%CVE-2026-60618HIGHVulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). EPSS 0.4%CVE-2026-61127HIGHVulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). SuppEPSS 0.4%CVE-2025-11007CRITICALCE21 Suite 2.2.1 - 2.3.1 - Missing Authorization to Unauthenticated Privilege Escalation via Plugin Settings UpdateEPSS 0.4%CVE-2026-60890HIGHVulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.4%CVE-2026-46965HIGHVulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). SEPSS 0.4%CVE-2026-60499HIGHVulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor). The supported vEPSS 0.4%CVE-2026-60602HIGHVulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing). The supported version EPSS 0.4%