Falhas do tipo CWE-602

174 resultados

Confiança inadequada em mecanismo de proteção implementado no cliente

O servidor delega uma função de segurança para o cliente executar, assumindo que o cliente vai implementar ou respeitar essa proteção. Na prática, o atacante controla o cliente e pode contornar ou desabilitar o mecanismo, comprometendo a segurança do servidor. É um erro fundamental de arquitetura: nunca confie em validações ou controles que rodem no lado do cliente.

Exemplo

Um servidor web que valida permissões apenas via JavaScript no navegador, permitindo ao usuário editar o HTML/JS localmente e contornar as restrições. Ou uma API que depende do cliente para não enviar dados além de um limite, sem validar no servidor.

Como mitigar

Implemente todas as validações críticas de segurança (autenticação, autorização, limite de taxa, validação de entrada) obrigatoriamente no servidor. Trate o cliente como potencialmente adversário e nunca confie em nada que venha dele sem re-validar no backend.

CVE-2026-14007MEDIUMInsufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation EPSS 0.3%CVE-2026-13930MEDIUMInsufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%CVE-2025-61197HIGHAn issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 EPSS 0.3%CVE-2026-14041HIGHInsufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation EPSS 0.3%CVE-2026-13903HIGHInsufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatiEPSS 0.3%CVE-2026-13901CRITICALInsufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendererEPSS 0.3%CVE-2026-14036HIGHInsufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatiEPSS 0.3%CVE-2026-14109CRITICALInsufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer pEPSS 0.3%CVE-2024-32512MEDIUMWordPress weForms plugin <= 1.6.20 - Form Submission Restriction Bypass vulnerabilityEPSS 0.3%CVE-2025-33137HIGHIBM Aspera Faspex data modificationEPSS 0.3%CVE-2024-52960MEDIUMA client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and beEPSS 0.3%CVE-2022-31233MEDIUMUnisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially expEPSS 0.3%CVE-2025-28168MEDIUMThe Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extensionEPSS 0.3%CVE-2025-12788MEDIUMHydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment BypassEPSS 0.3%CVE-2024-49824MEDIUMIBM Robotic Process Automation security bypassEPSS 0.3%CVE-2024-43188MEDIUMIBM Business Automation Workflow improper input validationEPSS 0.3%CVE-2025-7820HIGHSKT PayPal for WooCommerce <= 1.4 - Unauthenticated Payment BypassEPSS 0.3%CVE-2024-42340HIGHCyberArk - CWE-602: Client-Side Enforcement of Server-Side SecurityEPSS 0.3%CVE-2026-89175MEDIUMKingdom Communication Associated|Smart Video Intercom System - Client-Side AuthenticationEPSS 0.3%CVE-2026-67363HIGHJoomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2EPSS 0.3%