Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2026-0061MEDIUMIn multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay aEPSS 0.1%CVE-2025-62316LOWHCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configuredEPSS 0.1%CVE-2025-48639HIGHIn DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. ThiEPSS 0.1%CVE-2024-31324HIGHIn hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode firsEPSS 0.1%CVE-2022-20442HIGHIn onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a EPSS 0.1%CVE-2024-43084MEDIUMIn visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information diEPSS 0.1%CVE-2025-32349HIGHIn multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of pEPSS 0.1%CVE-2025-32350HIGHIn maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlaEPSS 0.1%CVE-2025-48597HIGHIn multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could leEPSS 0.1%CVE-2025-22417HIGHIn finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. TEPSS 0.1%CVE-2025-22419HIGHIn multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlaEPSS 0.1%CVE-2026-0036HIGHIn startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to locaEPSS 0.1%CVE-2026-28656HIGHIn multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to lEPSS 0.1%CVE-2026-28577HIGHIn addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to localEPSS 0.1%CVE-2026-84388CRITICALA improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM ChromeEPSS —CVE-2026-71177MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or FrEPSS —