CWE-602— Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.— MITRE CWE catalog
178 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-602page 3 of 4
- CVE-2026-11014MEDIUMCVSS 6.5EG 6.52026-06-04
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security sev…
- CVE-2026-5901MEDIUMCVSS 6.5EG 6.52026-04-08
Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chro…
- CVE-2026-30522MEDIUMCVSS 6.5EG 6.52026-04-01
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. Whil…
- CVE-2026-30521MEDIUMCVSS 6.5EG 6.52026-03-31
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend inter…
- CVE-2025-14687MEDIUMCVSS 6.5EG 6.52025-12-26
IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
- CVE-2025-36039MEDIUMCVSS 6.5EG 6.52025-07-31
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
- CVE-2025-1838MEDIUMCVSS 6.5EG 6.52025-05-03
IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.
- CVE-2024-49824MEDIUMCVSS 6.5EG 6.52025-01-18
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unautho…
- CVE-2023-42787MEDIUMCVSS 6.5EG 6.52023-10-10
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a…
- CVE-2023-0704MEDIUMCVSS 6.5EG 6.52023-02-07
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
- CVE-2022-3310MEDIUMCVSS 6.5EG 6.52022-11-01
Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium securi…
- CVE-2022-3047MEDIUMCVSS 6.5EG 6.52022-09-26
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.
- CVE-2020-27268MEDIUMCVSS 6.5EG 6.52021-01-19
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for de…
- CVE-2025-28168MEDIUMCVSS 6.4EG 6.42025-05-05
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload …
- CVE-2020-5345MEDIUMCVSS 6.4EG 6.42020-06-23
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated maliciou…
- CVE-2026-11184MEDIUMCVSS 6.3EG 6.32026-06-04
Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-5450MEDIUMCVSS 6.3EG 6.32025-07-08
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings …
- CVE-2024-39870MEDIUMCVSS 6.3EG 6.32024-07-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this mo…
- CVE-2025-46591MEDIUMCVSS 6.2EG 6.22025-05-06
Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-39218MEDIUMCVSS 6.1EG 6.12023-08-08
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
- CVE-2026-73627MEDIUMCVSS 6.0EG 6.02026-08-13
JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules b…
- CVE-2025-4527MEDIUMCVSS 5.9EG 5.92025-05-11
A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-…
- CVE-2025-56694MEDIUMCVSS 5.8EG 5.82025-08-27
Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protected photo albums.
- CVE-2017-14013MEDIUMCVSS 5.6EG 5.62017-10-17
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on the client side. This may allow an atta…
- CVE-2026-13929MEDIUMCVSS 5.5EG 5.52026-06-30
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)
- CVE-2026-56693MEDIUMCVSS 5.5EG 5.52026-06-23
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke …
- CVE-2025-41402MEDIUMCVSS 5.5EG 5.52025-10-23
Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server: 9.30 prior to vE…
- CVE-2024-41751MEDIUMCVSS 5.5EG 5.52025-07-23
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.
- CVE-2024-41750MEDIUMCVSS 5.5EG 5.52025-07-23
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.
- CVE-2023-3747MEDIUMCVSS 5.5EG 5.52023-09-07
Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lac…
- CVE-2023-23570MEDIUMCVSS 5.4EG 5.42023-12-18
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command Centre 8.90 prior to vEL8.90.1620 (MR2), al…
- CVE-2023-20172MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid cred…
- CVE-2023-20171MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid cred…
- CVE-2023-20106MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid cred…
- CVE-2026-100306MEDIUMCVSS 5.3EG 5.32026-09-25
TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without providi…
- CVE-2026-77320MEDIUMCVSS 5.3EG 5.32026-09-24
TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables share_map. Th…
- CVE-2026-89175MEDIUMCVSS 5.3EG 5.32026-09-11
Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configu…
- CVE-2026-77793MEDIUMCVSS 5.3EG 5.32026-09-02
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
- CVE-2026-84110MEDIUMCVSS 5.3EG 5.32026-09-01
A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may b…
- CVE-2026-14831MEDIUMCVSS 5.3EG 5.32026-08-06
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place b…
- CVE-2026-0808MEDIUMCVSS 5.3EG 5.32026-01-17
The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or rand…
- CVE-2025-12788MEDIUMCVSS 5.3EG 5.32025-11-11
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin ac…
- CVE-2025-54833MEDIUMCVSS 5.3EG 5.32025-07-31
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
- CVE-2025-27367MEDIUMCVSS 5.3EG 5.32025-07-08
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially cr…
- CVE-2025-43699MEDIUMCVSS 5.3EG 5.32025-06-10
Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check. This impacts OmniStudio: before Spring 2025
- CVE-2024-32685MEDIUMCVSS 5.3EG 5.32024-05-17
Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
- CVE-2024-32521MEDIUMCVSS 5.3EG 5.32024-05-17
Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
- CVE-2024-32512MEDIUMCVSS 5.3EG 5.32024-05-17
Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.
- CVE-2024-0701MEDIUMCVSS 5.3EG 5.32024-02-05
The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the …
- CVE-2023-0581MEDIUMCVSS 5.3EG 5.32023-01-30
The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via clien…
Map vulnerabilities like CWE-602 to your infrastructure
EchelonGraph correlates every CVE — across CWE-602 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →