Falhas do tipo CWE-602

174 resultados

Confiança inadequada em mecanismo de proteção implementado no cliente

O servidor delega uma função de segurança para o cliente executar, assumindo que o cliente vai implementar ou respeitar essa proteção. Na prática, o atacante controla o cliente e pode contornar ou desabilitar o mecanismo, comprometendo a segurança do servidor. É um erro fundamental de arquitetura: nunca confie em validações ou controles que rodem no lado do cliente.

Exemplo

Um servidor web que valida permissões apenas via JavaScript no navegador, permitindo ao usuário editar o HTML/JS localmente e contornar as restrições. Ou uma API que depende do cliente para não enviar dados além de um limite, sem validar no servidor.

Como mitigar

Implemente todas as validações críticas de segurança (autenticação, autorização, limite de taxa, validação de entrada) obrigatoriamente no servidor. Trate o cliente como potencialmente adversário e nunca confie em nada que venha dele sem re-validar no backend.

CVE-2026-84841MEDIUMtsi-coop tsi-dpdp-cms client-side enforcement of server-side securityEPSS 0.3%CVE-2026-30521MEDIUMA Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application EPSS 0.3%CVE-2026-11011HIGHInsufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised thEPSS 0.3%CVE-2026-14831MEDIUMEasy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration BypassEPSS 0.3%CVE-2026-59504CRITICALPriority – CWE-602: Client-Side Enforcement of Server-Side SecurityEPSS 0.3%CVE-2025-47697MEDIUMClient-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated attacker may bypass aEPSS 0.3%CVE-2026-13871MEDIUMInsufficient policy enforcement in GuestView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendeEPSS 0.3%CVE-2026-14054MEDIUMInsufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictioEPSS 0.3%CVE-2025-32359MEDIUMIn Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configEPSS 0.3%CVE-2026-17813MEDIUMInsufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigatEPSS 0.3%CVE-2026-17805MEDIUMInsufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation reEPSS 0.3%CVE-2026-11025MEDIUMInsufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass contentEPSS 0.3%CVE-2026-11018MEDIUMInsufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%CVE-2024-6620LOWHoneywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker couEPSS 0.3%CVE-2026-13724MEDIUMBusiness Logic Bypass in Gobito's Corporate Training Management SystemEPSS 0.3%CVE-2025-10161HIGHAuthentication Bypass in Turkguven's PerfektiveEPSS 0.3%CVE-2025-12115HIGHWPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price AlterationEPSS 0.3%CVE-2026-13795MEDIUMInsufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigatEPSS 0.3%CVE-2026-77026MEDIUMJoomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5EPSS 0.3%CVE-2026-15130MEDIUMInsufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation viEPSS 0.3%