Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-12457MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderEPSS 0.1%CVE-2024-36315MEDIUMImproper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensEPSS 0.1%CVE-2026-23553LOWx86: incomplete IBPB for vCPU isolationEPSS 0.1%CVE-2026-65406MEDIUMA logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GaEPSS 0.1%CVE-2026-20667HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4EPSS 0.1%CVE-2026-0011HIGHIn enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the codeEPSS 0.1%CVE-2026-65369MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.1%CVE-2026-82474HIGHSudo through 1.9.17p2 Intercept Policy Bypass via execveatEPSS 0.1%CVE-2026-48792MEDIUMpam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root executionEPSS 0.1%CVE-2026-1232MEDIUMAnti-Tamper Bypass in BeyondTrust Privilege Management for WindowsEPSS 0.1%CVE-2025-30431MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A maliciEPSS 0.1%CVE-2025-24284HIGHThis issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be ableEPSS 0.1%CVE-2026-8004MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2025-26402MEDIUMProtection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged softEPSS 0.1%CVE-2026-12214HIGHQihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComposeW protection mechanismEPSS 0.1%CVE-2025-24848MEDIUMProtection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow anEPSS 0.1%CVE-2026-84559MEDIUMA permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.1%CVE-2026-92074HIGHMitigation bypass in the Popup Blocker componentEPSS 0.1%CVE-2026-65339MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.EPSS 0.1%CVE-2026-85288MEDIUMNotepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialogEPSS 0.1%