Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-2803HIGHInformation disclosure, mitigation bypass in the Settings UI componentEPSS 0.3%CVE-2020-7320MEDIUMProtection Mechanism Failure in ENS for WindowsEPSS 0.3%CVE-2026-22013MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). EPSS 0.3%CVE-2026-17776MEDIUMPolicy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.3%CVE-2026-74883HIGHopenssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and ioEPSS 0.3%CVE-2026-0620MEDIUML2TP over IPSec Encryption Failure on ArcherAXE75EPSS 0.3%CVE-2026-8018HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbEPSS 0.3%CVE-2026-92959HIGHvm2 before 3.11.8 allowAsync Bypass via Promise ThenableEPSS 0.3%CVE-2026-11263MEDIUMInsufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had coEPSS 0.3%CVE-2025-20347MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.3%CVE-2026-13862MEDIUMInsufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an aEPSS 0.3%CVE-2026-32946MEDIUMEgress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)EPSS 0.3%CVE-2022-26774HIGHA logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able EPSS 0.3%CVE-2026-14058MEDIUMInsufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policEPSS 0.3%CVE-2026-12315CRITICALMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2026-16394CRITICALMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2026-16406CRITICALMitigation bypass in the Networking componentEPSS 0.3%CVE-2026-86800MEDIUMWP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility CheckEPSS 0.3%CVE-2026-86796MEDIUMWP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request ParametersEPSS 0.3%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%