VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (771)

page 38 of 39
  • CVE-2025-50324HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

  • CVE-2025-44090HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

  • CVE-2025-44089HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

  • CVE-2026-60166LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks…

  • CVE-2026-60164LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks…

  • CVE-2026-56585LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

  • CVE-2026-56087MedJul 15, 2026
    risk 0.00cvss 6.1epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data.

  • CVE-2026-47305HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2026-50661MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-34348MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

  • CVE-2026-15618MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the component exec Safety Guard. The manipulation results in protection mechanism failure. It is possible to launch the…

  • CVE-2026-15528LowJul 13, 2026
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in protection mechanism failure. Attacking…

  • CVE-2026-61437HigJul 10, 2026
    risk 0.00cvss 7.8epss 0.00

    PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the…

  • CVE-2026-60086MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt…

  • CVE-2026-59854MedJul 9, 2026
    risk 0.00cvss 4.9epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files…

  • CVE-2026-59207MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with…

  • CVE-2026-14625MedJul 4, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-14440MedJul 1, 2026
    risk 0.00cvss 6.8epss 0.00

    Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "letsencrypt.org"' without parameters). On…

  • CVE-2026-14409HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-3472LowJun 26, 2026
    risk 0.00cvss 3.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown…