Weaknesses of type CWE-841

75 results

Falta de Aplicação de Fluxo de Comportamento

Ocorre quando a aplicação não valida ou não força a ordem correta de operações que deveriam seguir um fluxo pré-definido. Um usuário pode pular etapas, executar ações fora da sequência esperada ou contornar regras de negócio, alterando o estado do sistema de forma indevida.

Example

Um sistema de compras que deveria exigir: (1) adicionar item ao carrinho, (2) informar endereço, (3) selecionar pagamento, (4) confirmar pedido. Se a aplicação não valida essas etapas no servidor, um atacante pode enviar uma requisição direto à etapa (4) sem passar pelas anteriores, criando pedidos sem endereço ou com valores manipulados.

How to mitigate

Implemente validação de estado no servidor: cada operação deve verificar se o usuário está na etapa correta antes de prosseguir. Use máquinas de estado (finite state machines) para modelar transições permitidas e rejeite requisições que violem o fluxo esperado. Nunca confie na ordem de execução do lado cliente.

CVE-2026-53637MEDIUMSylius: Cart FormComponent allows modification or deletion of an already-completed orderEPSS 0.3%CVE-2026-78103MEDIUMDimension Log Server Configuration Lock Bypass VulnerabilityEPSS 0.3%CVE-2025-52469HIGHChamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation BypassEPSS 0.3%CVE-2025-36333MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.3%CVE-2026-19993MEDIUMWebkul Bagisto RMA State Validation update-status behavioral workflowEPSS 0.3%CVE-2026-80195HIGHKimai before 2.63.0 Team Membership Removal via APIEPSS 0.3%CVE-2023-1383MEDIUMAn Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attaEPSS 0.3%CVE-2026-19208MEDIUMWonderTrader TraderDD.cpp queryTrades behavioral workflowEPSS 0.3%CVE-2026-75081MEDIUMWebkul Bagisto store behavioral workflowEPSS 0.3%CVE-2026-79083HIGHImproper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-46540MEDIUMNimiq light-blockchain: Light blockchain rebranch issueEPSS 0.3%CVE-2026-30574HIGHA Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application faEPSS 0.3%CVE-2026-78618MEDIUMDimension Business Logic Flaw Allows Chained Backend Object OperationsEPSS 0.3%CVE-2026-87503MEDIUMInappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social EPSS 0.3%CVE-2026-82423MEDIUMmacrozheng mall Payment Status Endpoint paySuccess behavioral workflowEPSS 0.3%CVE-2026-8477LOWImproper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticateEPSS 0.2%CVE-2023-5921HIGHFunction Bypass in GeodiEPSS 0.2%CVE-2025-48376LOWDnn.Platform's Site Import could use an external source with a crafted requestEPSS 0.2%CVE-2026-34582HIGHBotan has a TLS 1.3 certificate authentication bypassEPSS 0.2%CVE-2024-44128MEDIUMThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS EPSS 0.2%