Falhas do tipo CWE-636

57 resultados

Degradação para estado menos seguro em caso de erro

É quando o software, ao encontrar uma falha ou erro, recua automaticamente para um modo de operação menos seguro — como criptografia mais fraca, controle de acesso permissivo ou autenticação relaxada. O perigo: o atacante pode forçar o erro para explorar o fallback inseguro, transformando uma falha em brecha de segurança.

Exemplo

Um serviço tenta conectar com TLS 1.3, mas se falhar recai para SSL 3.0. Ou um sistema de autenticação multi-fator que, se o segundo fator não responder, aceita apenas a senha — permitindo ao atacante apenas bloquear o segundo fator para contornar a proteção.

Como mitigar

Nunca faça fallback para opções menos seguras: ou a operação funciona no nível de segurança exigido, ou ela falha explicitamente. Se há degradação inevitável (ex: compatibilidade), ela deve ser explícita, auditada e nunca automática em face de erro.

CVE-2026-54291HIGHSilent channel-binding authentication downgrade via unsupported certificate algorithmsEPSS 0.2%CVE-2026-41377MEDIUMOpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin InstallationEPSS 0.2%CVE-2026-35205HIGHHelm's plugin verification fails open when .prov is missing, allowing unsigned plugin installEPSS 0.2%CVE-2026-86120MEDIUMAPITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permission GuardEPSS 0.2%CVE-2026-85649HIGH(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root uEPSS 0.2%CVE-2026-45781LOWMCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claimsEPSS 0.2%CVE-2026-53852LOWOpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairingEPSS 0.2%CVE-2025-54870HIGHVTun-ng's failure to initialize encryption modules may cause reversion to plaintextEPSS 0.2%CVE-2026-53837MEDIUMOpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event HandlersEPSS 0.2%CVE-2023-4030HIGHA vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover toEPSS 0.2%CVE-2026-82018MEDIUMIGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf FileEPSS 0.2%CVE-2026-35042HIGHfast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)EPSS 0.2%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2026-49317LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-49318LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-82744LOWAsh.Reactor change step fails open, skipping a change when its where guard raisesEPSS 0.1%CVE-2026-32970LOWOpenClaw < 2026.3.11 - Credential Fallback Logic Bypass via Unavailable Local Auth SecretRefsEPSS 0.1%