Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-92956CRITICALvm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreamingEPSS 0.6%CVE-2026-82855CRITICAL@hulumi/policies before 1.3.2 Evidence Validation BypassEPSS 0.6%CVE-2026-92066CRITICALSandbox escape in the Profile Backup componentEPSS 0.6%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.6%CVE-2024-21423MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-28286MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-47686CRITICALvm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCEEPSS 0.6%CVE-2025-43413HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, mEPSS 0.6%CVE-2026-84809HIGHTencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python BytecodeEPSS 0.6%CVE-2020-28396—A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-80EPSS 0.6%CVE-2025-48003MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-2768CRITICALSandbox escape in the Storage: IndexedDB componentEPSS 0.6%CVE-2025-65319CRITICALWhen using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-WeEPSS 0.6%CVE-2022-43433MEDIUMJenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in worEPSS 0.6%CVE-2020-16198MEDIUMPhilips Clinical Collaboration Platform Protection Mechanism FailureEPSS 0.6%CVE-2026-14535HIGHFickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()EPSS 0.6%CVE-2025-65318CRITICALWhen using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-WebEPSS 0.6%CVE-2026-74896CRITICALopenssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute TraversalEPSS 0.6%CVE-2026-57120MEDIUMPraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunderEPSS 0.6%CVE-2024-27713HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP ResEPSS 0.6%