Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-0012MEDIUMIn setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This coulEPSS 0.1%CVE-2025-48605HIGHIn multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead EPSS 0.1%CVE-2025-48602HIGHIn exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic erroEPSS 0.1%CVE-2026-0293MEDIUMPrisma Access Agent: Anti-Tamper Protection Bypass on WindowsEPSS 0.1%CVE-2026-56881HIGHIn enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2026-56941HIGHIn multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2025-27700HIGHThere is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2026-0306MEDIUMPrisma Access Agent: EndPoint DLP Bypass Vulnerability on WindowsEPSS 0.1%CVE-2025-0089HIGHIn multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalatEPSS 0.1%CVE-2026-7913HIGHInsufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilegeEPSS 0.1%CVE-2026-56973MEDIUMIn multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2026-56979MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2026-55302MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2026-55304MEDIUMIn addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2026-58767MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to locEPSS 0.1%CVE-2026-58765MEDIUMIn GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with SystemEPSS 0.1%CVE-2026-58747MEDIUMIn smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2026-58755MEDIUMIn smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead tEPSS 0.1%CVE-2026-28658HIGHIn findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation EPSS 0.1%CVE-2026-58678HIGHIn Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege withEPSS 0.1%