Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-74896CRITICALopenssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute TraversalEPSS 0.3%CVE-2026-19152HIGHInsufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renEPSS 0.3%CVE-2025-11260MEDIUMWP Headless CMS Framework <= 1.15 - Unauthenticated Protection Mechanism BypassEPSS 0.3%CVE-2026-80198HIGHKimai before 2.56.0 Information Disclosure via config() Twig FunctionEPSS 0.3%CVE-2026-44071LOWFORTIFY_SOURCE disabledEPSS 0.3%CVE-2020-10598In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability eEPSS 0.3%CVE-2026-14101CRITICALInsufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the EPSS 0.3%CVE-2026-14151HIGHInappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2022-26696HIGHThis issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed process may be ableEPSS 0.3%CVE-2025-8032HIGHXSLT documents could bypass CSPEPSS 0.3%CVE-2026-78552MEDIUMValidation Bypass in Okta Access Gateway Custom DirectivesEPSS 0.3%CVE-2026-79683HIGHDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploEPSS 0.3%CVE-2025-15618CRITICALBusiness::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret keyEPSS 0.3%CVE-2023-5875LOWLack of Hardening against media exploitation from a remote originEPSS 0.3%CVE-2022-32537MEDIUMMedtronic MiniMed 600 Series Pump System Communication IssueEPSS 0.3%CVE-2026-74983HIGHMitigation bypass in the Data Loss Prevention componentEPSS 0.3%CVE-2026-82855CRITICAL@hulumi/policies before 1.3.2 Evidence Validation BypassEPSS 0.3%CVE-2026-20702HIGHProtection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. UnprivilEPSS 0.3%CVE-2026-87808HIGHSiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlockEPSS 0.3%CVE-2026-70608HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathEPSS 0.3%