Fallos del tipo CWE-306

2628 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-10267MEDIUMNewType Infortech|NUP Portal - Missing AuthenticationEPSS 0.4%CVE-2025-7774HIGHRockwell Automation ArmorBlock 5000 I/O – Web Server VulnerabilitiesEPSS 0.4%CVE-2024-8057MEDIUMImproper Access Control in danswer-ai/danswerEPSS 0.4%CVE-2024-36555CRITICALBuilt-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch EPSS 0.4%CVE-2026-79645HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%CVE-2024-8074CRITICALSensetive Data Exposure in Nomysoft Informatics' NomysemEPSS 0.4%CVE-2025-48391HIGHIn JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in APIEPSS 0.4%CVE-2025-11171MEDIUMChartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative FunctionEPSS 0.4%CVE-2026-57909CRITICALWatchGuard Agent path traversal allows unauthenticated remote code executionEPSS 0.4%CVE-2026-34266MEDIUMVulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supporEPSS 0.4%CVE-2026-34280MEDIUMVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supporteEPSS 0.4%CVE-2024-41967HIGHWAGO: Boot Mode Manipulation in Multiple DevicesEPSS 0.4%CVE-2025-26468HIGHCyberData 011209 SIP Emergency Intercom Missing Authentication for Critical FunctionEPSS 0.4%CVE-2024-7726MEDIUMArbitrary Code execution via exposed JTAG port in Kioxia CM6, PM6, PM7EPSS 0.4%CVE-2026-10577CRITICALRockwell Automation 1715 Redundant IO – Access Control VulnerabilityEPSS 0.4%CVE-2026-78255HIGHDJI Drone HTTP Media Server Allows Unauthenticated Access to Stored MediaEPSS 0.4%CVE-2026-39393HIGHPost-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4msEPSS 0.4%CVE-2026-66875HIGHMira Hormone Monitor, Mira Android App Missing authentication for critical functionEPSS 0.4%CVE-2026-50507MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-4476MEDIUMYi Technology YI Home Camera CGI Endpoint ipc missing authenticationEPSS 0.4%