VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (895)

page 44 of 45
  • CVE-2026-64728MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy.

  • CVE-2026-64708MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper checks.

  • CVE-2025-50330HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

  • CVE-2025-50325MedJul 22, 2026
    risk 0.00cvss 5.4epss 0.00

    BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip

  • CVE-2025-50324HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

  • CVE-2025-44090HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

  • CVE-2025-44089HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

  • CVE-2026-60166LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks…

  • CVE-2026-60164LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks…

  • CVE-2026-56585LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

  • CVE-2026-56087MedJul 15, 2026
    risk 0.00cvss 6.1epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data.

  • CVE-2026-47305HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2026-50661MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-34348MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

  • CVE-2026-15618MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the component exec Safety Guard. The manipulation results in protection mechanism failure. It is possible to launch the…

  • CVE-2026-15528LowJul 13, 2026
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in protection mechanism failure. Attacking…

  • CVE-2026-61437HigJul 10, 2026
    risk 0.00cvss 7.8epss 0.00

    PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the…

  • CVE-2026-60086MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt…

  • CVE-2026-59854MedJul 9, 2026
    risk 0.00cvss 4.9epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files…

  • CVE-2026-59207MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with…