CWE-602— Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.— MITRE CWE catalog
169 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-602page 4 of 4
- CVE-2026-44567HIGHCVSS 7.3EG 7.32026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of user. By default, when Open WebUI is confi…
- CVE-2026-45274MEDIUMCVSS 6.9EG 6.92026-08-19
MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though th…
- CVE-2026-46485HIGHCVSS 8.2EG 8.22026-07-15
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality des…
- CVE-2026-54104HIGHCVSS 8.8EG 8.82026-06-18
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter witho…
- CVE-2026-56256HIGHCVSS 7.1EG 7.12026-06-24
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the backe…
- CVE-2026-56693MEDIUMCVSS 5.5EG 5.52026-06-23
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke …
- CVE-2026-57912HIGHCVSS 7.5EG 7.52026-06-26
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
- CVE-2026-57913HIGHCVSS 7.5EG 7.52026-06-26
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
- CVE-2026-5901MEDIUMCVSS 6.5EG 6.52026-04-08
Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chro…
- CVE-2026-59504CRITICALCVSS 9.1EG 9.12026-08-13
: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All…
- CVE-2026-63301HIGHCVSS 7.0EG 7.02026-07-28
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent serve…
- CVE-2026-64813CRITICALCVSS 10.0EG 10.02026-07-23
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- CVE-2026-65051MEDIUMCVSS 6.5EG 6.52026-07-21
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over ser…
- CVE-2026-65938MEDIUMCVSS 4.3EG 4.32026-08-12
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
- CVE-2026-67363HIGHCVSS 7.7EG 7.72026-08-19
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment g…
- CVE-2026-72867CRITICALCVSS 9.9EG 9.92026-08-10
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct…
- CVE-2026-73267HIGHCVSS 7.7EG 7.72026-08-21
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allow…
- CVE-2026-73627MEDIUMCVSS 6.0EG 6.02026-08-13
JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules b…
- CVE-2026-77026MEDIUMCVSS 6.9EG 6.92026-08-20
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
Map vulnerabilities like CWE-602 to your infrastructure
EchelonGraph correlates every CVE — across CWE-602 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →