Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-77401MEDIUMZope AccessControl: Information disclosure through Python string `format` and `format_map` functionsEPSS 0.5%CVE-2026-45655MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-47305HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-3965MEDIUMwhyour qinglong API express.ts protection mechanismEPSS 0.5%CVE-2026-91949CRITICALFreeRDP 3.0.0 through 3.30.0 Protocol Negotiation BypassEPSS 0.5%CVE-2026-54981HIGHVisual Studio Code Python Extension Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-13794MEDIUMHide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page DisclosureEPSS 0.5%CVE-2018-0250—A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 18EPSS 0.5%CVE-2026-55366CRITICALIn IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalationEPSS 0.5%CVE-2023-52378CRITICALVulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause featureEPSS 0.5%CVE-2026-75874CRITICALSandbox escape in the Remote Settings Client componentEPSS 0.5%CVE-2026-48037MEDIUMHulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub postureEPSS 0.5%CVE-2026-79988HIGHAuthenticated RCE through Twig sandbox escapeEPSS 0.5%CVE-2026-39421MEDIUMMaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotectEPSS 0.4%CVE-2026-70608HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathEPSS 0.4%CVE-2026-8959CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.4%CVE-2026-92959HIGHvm2 before 3.11.8 allowAsync Bypass via Promise ThenableEPSS 0.4%CVE-2026-59207HIGHn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP ConnectorEPSS 0.4%CVE-2026-20702HIGHProtection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. UnprivilEPSS 0.4%CVE-2022-46762HIGHThe memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.EPSS 0.4%