Falhas do tipo CWE-693

838 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-54013HIGHOpen WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUIEPSS 0.3%CVE-2026-70601HIGHElectron: Context isolation bypass via Function.prototype.bind hijackEPSS 0.3%CVE-2026-17764MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a cEPSS 0.3%CVE-2026-17931MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%CVE-2026-17674MEDIUMInappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy viaEPSS 0.3%CVE-2026-10950MEDIUMInsufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2026-10944MEDIUMInsufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2023-0002MEDIUMCortex XDR Agent: Product Disruption by Local Windows UserEPSS 0.3%CVE-2026-70444MEDIUMA missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission tEPSS 0.3%CVE-2025-48534HIGHIn getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. ThisEPSS 0.3%CVE-2024-6153HIGHParallels Desktop Updater Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.3%CVE-2022-42848HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. EPSS 0.3%CVE-2026-44000MEDIUMvm2: sandbox boundary bypass via host Promise resolution preserving host object identityEPSS 0.3%CVE-2024-38874MEDIUMAn issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the maEPSS 0.3%CVE-2023-20573LOWDebug Exception Delivery in Secure Nested PagingEPSS 0.3%CVE-2026-59277LOWSpring Security InetAddressMatchers Incomplete Internal Network ClassificationEPSS 0.3%CVE-2024-46976MEDIUMCircumvention of cross site scripting Protection in @backstage/plugin-techdocs-backendEPSS 0.3%CVE-2025-59033HIGHThe Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only tEPSS 0.3%CVE-2026-8583MEDIUMInsufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-8585HIGHInappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.3%