Fallos del tipo CWE-306

2629 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2026-4476MEDIUMYi Technology YI Home Camera CGI Endpoint ipc missing authenticationEPSS 0.4%CVE-2026-45567HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gptEPSS 0.4%CVE-2024-5143MEDIUMA user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server EPSS 0.4%CVE-2024-55585CRITICALIn the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricEPSS 0.4%CVE-2026-8185MEDIUMUGREEN CM933 Administrative missing authenticationEPSS 0.4%CVE-2026-25058HIGHVexa's unauthenticated internal transcript endpoint exposed by defaultEPSS 0.4%CVE-2026-45088HIGHDalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server ModeEPSS 0.4%CVE-2026-40184LOWUnauthenticated Access to Uploaded Files in TREKEPSS 0.4%CVE-2025-48742MEDIUMThe installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.EPSS 0.4%CVE-2025-68640MEDIUMThe Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate dEPSS 0.4%CVE-2026-45089HIGHDalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server ModeEPSS 0.4%CVE-2026-18771HIGHMissing Authentication for Critical Function in TMT Machine's Talassoft Industrial Management SoftwareEPSS 0.4%CVE-2026-89176HIGHHowyar|WeenyGenius - Missing AuthenticationEPSS 0.4%CVE-2026-87200HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2025-32876MEDIUMAn issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure EPSS 0.4%CVE-2026-10617MEDIUMnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authenticationEPSS 0.4%CVE-2025-61752HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2026-35450MEDIUMWWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.phpEPSS 0.4%CVE-2025-27214CRITICALA Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical oEPSS 0.4%CVE-2026-79961MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing AuthenticaEPSS 0.4%