Weaknesses of type CWE-636

58 results

Fallback para estado menos seguro em caso de falha

É quando o software, ao enfrentar um erro ou falha, retrocede automaticamente para uma configuração de segurança mais fraca em vez de interromper a operação ou falhar de forma segura. Exemplo: ao não conseguir usar TLS 1.3, cai para SSL 3.0; ou quando falha a autenticação forte, permite login sem senha. O risco é que um atacante provoca intencionalmente a falha para forçar o sistema a usar proteções inadequadas.

Example

Um cliente VPN que não consegue estabelecer conexão com encriptação AES-256 automaticamente downgrade para DES (obsoleto e fraco). Um servidor web que, ao falhar a validação de certificado ECDSA, aceita conexões sem TLS. Um sistema de login que, se o servidor de autenticação multifator cair, permite acesso só com senha.

How to mitigate

Nunca faça fallback automático para algo menos seguro — interrompa a operação ou lance erro explícito. Implemente validação de segurança mínima obrigatória (nunca abaixe desta linha) e documente claramente quais são as configurações de segurança aceitáveis. Teste cenários de falha para garantir que o sistema falha seguro, não permissivo.

CVE-2026-54291HIGHSilent channel-binding authentication downgrade via unsupported certificate algorithmsEPSS 0.2%CVE-2026-41377MEDIUMOpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin InstallationEPSS 0.2%CVE-2026-35205HIGHHelm's plugin verification fails open when .prov is missing, allowing unsigned plugin installEPSS 0.2%CVE-2026-86120MEDIUMAPITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permission GuardEPSS 0.2%CVE-2026-85649HIGH(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root uEPSS 0.2%CVE-2026-53852LOWOpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairingEPSS 0.2%CVE-2026-45781LOWMCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claimsEPSS 0.2%CVE-2025-54870HIGHVTun-ng's failure to initialize encryption modules may cause reversion to plaintextEPSS 0.2%CVE-2023-4030HIGHA vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover toEPSS 0.2%CVE-2026-53837MEDIUMOpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event HandlersEPSS 0.2%CVE-2026-82018MEDIUMIGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf FileEPSS 0.2%CVE-2026-35042HIGHfast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)EPSS 0.2%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2026-49317LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-49318LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-82744LOWAsh.Reactor change step fails open, skipping a change when its where guard raisesEPSS 0.1%CVE-2026-32970LOWOpenClaw < 2026.3.11 - Credential Fallback Logic Bypass via Unavailable Local Auth SecretRefsEPSS 0.1%CVE-2026-95676HIGHAuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication BypassEPSS