CWE-602— Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.— MITRE CWE catalog
178 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-602page 4 of 4
- CVE-2024-43188MEDIUMCVSS 4.9EG 4.92024-09-18
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.
- CVE-2025-36093MEDIUMCVSS 4.8EG 4.82025-11-03
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
- CVE-2025-32359MEDIUMCVSS 4.8EG 4.82025-04-05
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was …
- CVE-2026-42329MEDIUMCVSS 4.7EG 4.72026-06-04
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker can misuse it to redirect the user to a malicious website cont…
- CVE-2024-6831MEDIUMCVSS 4.4EG 4.42024-11-26
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched versions for the highli…
- CVE-2026-65938MEDIUMCVSS 4.3EG 4.32026-08-12
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
- CVE-2026-17960MEDIUMCVSS 4.3EG 4.32026-07-30
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-13724MEDIUMCVSS 4.3EG 4.32026-07-20
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Tra…
- CVE-2026-15130MEDIUMCVSS 4.3EG 4.32026-07-08
Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-14075MEDIUMCVSS 4.3EG 4.32026-06-30
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14054MEDIUMCVSS 4.3EG 4.32026-06-30
Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-14047MEDIUMCVSS 4.3EG 4.32026-06-30
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium sec…
- CVE-2026-11267MEDIUMCVSS 4.3EG 4.32026-06-04
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium sec…
- CVE-2026-11062MEDIUMCVSS 4.3EG 4.32026-06-04
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension…
- CVE-2026-39415MEDIUMCVSS 4.3EG 4.32026-04-08
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by students before submission.…
- CVE-2026-3941MEDIUMCVSS 4.3EG 4.32026-03-11
Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2025-36410MEDIUMCVSS 4.3EG 4.32026-01-20
IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.
- CVE-2025-8792MEDIUMCVSS 4.3EG 4.32025-08-10
A vulnerability classified as problematic has been found in LitmusChaos Litmus up to 3.19.0. Affected is an unknown function. The manipulation leads to client-side enforcement of server-side security. It is possible to launch the attack re…
- CVE-2024-52960MEDIUMCVSS 4.3EG 4.32025-03-11
A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthor…
- CVE-2024-20476MEDIUMCVSS 4.3EG 4.32024-11-06
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due to lack of server-…
- CVE-2023-48789MEDIUMCVSS 4.3EG 4.32024-06-03
A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
- CVE-2023-30955MEDIUMCVSS 4.3EG 4.32023-06-29
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interac…
- CVE-2025-2139LOWCVSS 3.5EG 3.52025-10-12
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.
- CVE-2025-2138LOWCVSS 3.5EG 3.52025-10-12
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.
- CVE-2024-6620LOWCVSS 3.5EG 3.52024-07-29
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or cl…
- CVE-2026-23859LOWCVSS 2.7EG 2.72026-02-24
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to Protection mechan…
- CVE-2025-36102LOWCVSS 2.7EG 2.72025-12-08
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-…
- CVE-2021-21544LOWCVSS 2.7EG 2.72021-04-30
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under t…
Map vulnerabilities like CWE-602 to your infrastructure
EchelonGraph correlates every CVE — across CWE-602 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →