Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-8011MEDIUMInsufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a EPSS 0.3%CVE-2026-8014MEDIUMInappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crEPSS 0.3%CVE-2022-26774HIGHA logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able EPSS 0.3%CVE-2026-22013MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). EPSS 0.3%CVE-2026-6774MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2020-7320MEDIUMProtection Mechanism Failure in ENS for WindowsEPSS 0.3%CVE-2026-17779MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation viEPSS 0.3%CVE-2026-11263MEDIUMInsufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had coEPSS 0.3%CVE-2026-0620MEDIUML2TP over IPSec Encryption Failure on ArcherAXE75EPSS 0.3%CVE-2025-20347MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.3%CVE-2026-73083HIGHActivepieces: V8 Isolate Sandbox Bypass via importFresh Module LoadingEPSS 0.3%CVE-2026-13862MEDIUMInsufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an aEPSS 0.3%CVE-2026-17943MEDIUMInappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy vEPSS 0.3%CVE-2026-5911MEDIUMPolicy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crEPSS 0.3%CVE-2026-14058MEDIUMInsufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policEPSS 0.3%CVE-2026-16394CRITICALMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2026-16406CRITICALMitigation bypass in the Networking componentEPSS 0.3%CVE-2026-12315CRITICALMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%CVE-2026-12302MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.2%