Fallos del tipo CWE-306

2627 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-60365CRITICALVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for EPSS 0.4%CVE-2026-34285CRITICALVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that iEPSS 0.4%CVE-2026-61171CRITICALVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.EPSS 0.4%CVE-2025-15026CRITICALUnauthenticated configuration import allows administrative account creation using AWIE componentEPSS 0.4%CVE-2026-17348MEDIUMpgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)EPSS 0.4%CVE-2024-47865MEDIUMMissing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerabEPSS 0.4%CVE-2026-83461HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2023-41255HIGHThe vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abuEPSS 0.4%CVE-2026-83266HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that EPSS 0.4%CVE-2026-45577MEDIUMNeotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypassEPSS 0.4%CVE-2024-46293CRITICALSourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for adEPSS 0.4%CVE-2024-26263MEDIUMEBM Technologies RISWEB - Improper Access ControlEPSS 0.4%CVE-2025-55222HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70EPSS 0.4%CVE-2026-42331HIGHFOSSBilling missing authorization in guest Invoice API endpointsEPSS 0.4%CVE-2026-5749HIGHInadequate access control vulnerability in FullstepEPSS 0.4%CVE-2025-32738MEDIUMMissing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlieEPSS 0.4%CVE-2025-55221HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70EPSS 0.4%CVE-2026-77248HIGHMCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transportEPSS 0.4%CVE-2026-58071HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal AdministEPSS 0.4%CVE-2024-32764CRITICALmyQNAPcloud LinkEPSS 0.4%