Fallos del tipo CWE-306

2628 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-5749HIGHInadequate access control vulnerability in FullstepEPSS 0.4%CVE-2026-74245MEDIUMQuay: unauthenticated exported logs download in quayEPSS 0.4%CVE-2026-60580HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2026-29132MEDIUMESWmail-Verify BypassEPSS 0.4%CVE-2026-59971CRITICALMySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)EPSS 0.4%CVE-2022-48289HIGHThe bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2022-48300HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2025-30111HIGHOn IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized usEPSS 0.4%CVE-2022-48288HIGHThe bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2026-15581HIGHTrustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wideEPSS 0.4%CVE-2022-48299HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2024-6582MEDIUMBroken Access Control in lunary-ai/lunaryEPSS 0.4%CVE-2025-66049HIGHUnprotected RTSP stream in Vivotek IP7137 camerasEPSS 0.4%CVE-2026-46789CRITICALVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that EPSS 0.4%CVE-2026-19971MEDIUMLB-Link WR1210M Backup Endpoint backup.cgi main missing authenticationEPSS 0.4%CVE-2026-86259CRITICALOpenMAIC before 1.0.1 SSRF via Environment-Gated URL ValidationEPSS 0.4%CVE-2026-60967HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported versions that are affecEPSS 0.4%CVE-2025-8279HIGHMissing Authentication for Critical Function in GitLab Language ServerEPSS 0.4%CVE-2025-41654HIGHPEPPERL+FUCHS: Profinet Gateway LB8122A.1.EL – Device is affected by information disclosure via the SNMP protocolEPSS 0.4%CVE-2026-60356HIGHVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%