Fallos del tipo CWE-602

174 resultados

Confiança em mecanismo de segurança implementado no cliente

O servidor delega a responsabilidade de uma proteção de segurança para o cliente executar, assumindo que ele vai cumprir. Isso é perigoso porque um atacante controla o cliente e pode simplesmente ignorar, contornar ou desabilitar essa proteção, deixando o servidor vulnerável.

Ejemplo

Um servidor web que valida permissões de acesso apenas via JavaScript no navegador, sem verificar novamente no backend. Um atacante desabilita o JavaScript ou intercepta a requisição, acessando dados que não deveria.

Cómo mitigar

Implemente toda validação crítica de segurança no servidor, nunca confie em verificações feitas apenas no cliente. O cliente pode fazer validação por UX, mas o servidor deve sempre validar independentemente autenticação, autorização, entrada de dados e regras de negócio.

CVE-2026-14007MEDIUMInsufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation EPSS 0.3%CVE-2026-13930MEDIUMInsufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%CVE-2026-13919MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-14041HIGHInsufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation EPSS 0.3%CVE-2026-13903HIGHInsufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatiEPSS 0.3%CVE-2026-13901CRITICALInsufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendererEPSS 0.3%CVE-2026-14036HIGHInsufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatiEPSS 0.3%CVE-2026-14109CRITICALInsufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer pEPSS 0.3%CVE-2024-32512MEDIUMWordPress weForms plugin <= 1.6.20 - Form Submission Restriction Bypass vulnerabilityEPSS 0.3%CVE-2025-33137HIGHIBM Aspera Faspex data modificationEPSS 0.3%CVE-2024-52960MEDIUMA client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and beEPSS 0.3%CVE-2022-31233MEDIUMUnisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially expEPSS 0.3%CVE-2025-28168MEDIUMThe Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extensionEPSS 0.3%CVE-2025-12788MEDIUMHydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment BypassEPSS 0.3%CVE-2024-49824MEDIUMIBM Robotic Process Automation security bypassEPSS 0.3%CVE-2024-43188MEDIUMIBM Business Automation Workflow improper input validationEPSS 0.3%CVE-2025-7820HIGHSKT PayPal for WooCommerce <= 1.4 - Unauthenticated Payment BypassEPSS 0.3%CVE-2024-42340HIGHCyberArk - CWE-602: Client-Side Enforcement of Server-Side SecurityEPSS 0.3%CVE-2026-89175MEDIUMKingdom Communication Associated|Smart Video Intercom System - Client-Side AuthenticationEPSS 0.3%CVE-2026-67363HIGHJoomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2EPSS 0.3%