Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-17676CRITICALInappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2025-12554MEDIUMMissing Security HeadersEPSS 0.3%CVE-2026-17669CRITICALInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perfoEPSS 0.3%CVE-2026-17710CRITICALInappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendeEPSS 0.3%CVE-2026-17856CRITICALInappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renEPSS 0.3%CVE-2026-13909CRITICALInsufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2026-14037CRITICALInsufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2026-18015CRITICALInappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbEPSS 0.3%CVE-2026-8018HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbEPSS 0.3%CVE-2025-6427CRITICALconnect-src Content Security Policy restriction could be bypassedEPSS 0.3%CVE-2023-45372—An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.EPSS 0.3%CVE-2026-42261HIGHPromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`EPSS 0.3%CVE-2026-86894HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandboEPSS 0.3%CVE-2026-79638MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 0.3%CVE-2025-11260MEDIUMWP Headless CMS Framework <= 1.15 - Unauthenticated Protection Mechanism BypassEPSS 0.3%CVE-2020-10598—In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability eEPSS 0.3%CVE-2026-45656HIGHUEFI Secure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-14101CRITICALInsufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the EPSS 0.3%CVE-2026-39452MEDIUMProtection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escaEPSS 0.3%CVE-2026-14151HIGHInappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%