Weaknesses of type CWE-693

820 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-55302MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2026-28658HIGHIn findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation EPSS 0.1%CVE-2026-0045HIGHIn bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. TEPSS 0.1%CVE-2025-48652HIGHIn performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This coulEPSS 0.1%CVE-2026-28668HIGHIn LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalatioEPSS 0.1%CVE-2026-0087HIGHIn approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic EPSS 0.1%CVE-2025-48554MEDIUMIn handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the coEPSS 0.1%CVE-2026-55359HIGHIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2026-28664HIGHIn WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalEPSS 0.1%CVE-2026-0077HIGHIn resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the cEPSS 0.1%CVE-2026-56941HIGHIn multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2025-48649HIGHIn multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead toEPSS 0.1%CVE-2026-56979MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2025-22431MEDIUMIn multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due EPSS 0.1%CVE-2026-56970HIGHIn multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of priviEPSS 0.1%CVE-2026-56973MEDIUMIn multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2026-28612HIGHIn resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. EPSS 0.1%CVE-2026-58755MEDIUMIn smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead tEPSS 0.1%CVE-2026-0187MEDIUMIn gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could leadEPSS 0.1%CVE-2026-0186MEDIUMIn ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalEPSS 0.1%