Weaknesses of type CWE-636

60 results

Fallback para estado menos seguro em caso de falha

É quando o software, ao enfrentar um erro ou falha, retrocede automaticamente para uma configuração de segurança mais fraca em vez de interromper a operação ou falhar de forma segura. Exemplo: ao não conseguir usar TLS 1.3, cai para SSL 3.0; ou quando falha a autenticação forte, permite login sem senha. O risco é que um atacante provoca intencionalmente a falha para forçar o sistema a usar proteções inadequadas.

Example

Um cliente VPN que não consegue estabelecer conexão com encriptação AES-256 automaticamente downgrade para DES (obsoleto e fraco). Um servidor web que, ao falhar a validação de certificado ECDSA, aceita conexões sem TLS. Um sistema de login que, se o servidor de autenticação multifator cair, permite acesso só com senha.

How to mitigate

Nunca faça fallback automático para algo menos seguro — interrompa a operação ou lance erro explícito. Implemente validação de segurança mínima obrigatória (nunca abaixe desta linha) e documente claramente quais são as configurações de segurança aceitáveis. Teste cenários de falha para garantir que o sistema falha seguro, não permissivo.

CVE-2026-69306HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-61595HIGHdjust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' dataEPSS 0.4%CVE-2026-18329HIGHNGINX ngx_http_js_module vulnerabilityEPSS 0.4%CVE-2026-77560HIGHTinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist forEPSS 0.3%CVE-2026-46482MEDIUMMyBB: Security Question insufficient validationEPSS 0.3%CVE-2026-81379HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-40249MEDIUMfree5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errorsEPSS 0.3%CVE-2025-41759MEDIUMUse of wildcard (“*” or “all”) in Block listEPSS 0.3%CVE-2025-41760MEDIUMPass filter with Empty TableEPSS 0.3%CVE-2026-42423HIGHOpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout FallbackEPSS 0.3%CVE-2023-22943MEDIUMModular Input REST API Requests Connect via HTTP after Certificate Validation Failure in Splunk Add-on Builder and Splunk CloudConnect SDKEPSS 0.3%CVE-2026-41334HIGHOpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard BypassEPSS 0.3%CVE-2026-42246HIGHnet-imap vulnerable to STARTTLS stripping via invalid response timingEPSS 0.3%CVE-2024-2660MEDIUMVault TLS Cert Auth Method Did Not Correctly Validate OCSP ResponsesEPSS 0.3%CVE-2026-62235LOWGrav Flex-Objects < 1.4.3 Authorization Bypass via APIEPSS 0.3%CVE-2026-53712HIGHSCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithmsEPSS 0.3%CVE-2026-44094HIGHFallback to second RAUC slot with default credentialsEPSS 0.3%CVE-2026-27448LOWpyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callbackEPSS 0.2%CVE-2026-92591HIGHCraft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via InstallerEPSS 0.2%CVE-2021-3614MEDIUMA vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under cEPSS 0.2%