CWE-693— Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.— MITRE CWE catalog
739 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-693page 11 of 15
- CVE-2026-17079MEDIUMCVSS 4.3EG 6.32026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
- CVE-2026-17659MEDIUMCVSS 4.2EG 4.22026-07-30
Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-17669CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-17674MEDIUMCVSS 6.5EG 6.52026-07-30
Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-17676CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…
- CVE-2026-17677HIGHCVSS 8.8EG 8.82026-07-30
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-17695CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-17710CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sev…
- CVE-2026-17764MEDIUMCVSS 6.5EG 6.52026-07-30
Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-17776MEDIUMCVSS 5.8EG 5.82026-07-30
Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-17779MEDIUMCVSS 5.4EG 5.42026-07-30
Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-17856CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security s…
- CVE-2026-17865CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security se…
- CVE-2026-17882MEDIUMCVSS 6.5EG 6.52026-07-30
Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)
- CVE-2026-17899HIGHCVSS 8.8EG 8.82026-07-30
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium securit…
- CVE-2026-17919MEDIUMCVSS 6.8EG 6.82026-07-30
Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)
- CVE-2026-17923MEDIUMCVSS 6.5EG 6.52026-07-30
Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low)
- CVE-2026-17931MEDIUMCVSS 6.5EG 6.52026-07-30
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-17936MEDIUMCVSS 6.5EG 6.52026-07-30
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security…
- CVE-2026-17943MEDIUMCVSS 4.3EG 4.32026-07-30
Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-18015CRITICALCVSS 9.6EG 9.62026-07-30
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-18428HIGHCVSS 8.8EG 8.82026-08-13
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to…
- CVE-2026-19150HIGHCVSS 8.8EG 8.82026-08-06
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-19152HIGHCVSS 8.3EG 8.32026-08-06
Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security s…
- CVE-2026-19168HIGHCVSS 8.8EG 8.82026-08-06
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-20665MEDIUMCVSS 6.5EG 6.52026-03-25
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafte…
- CVE-2026-20667HIGHCVSS 8.8EG 8.82026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
- CVE-2026-20701HIGHCVSS 7.5EG 7.52026-03-25
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.
- CVE-2026-20702HIGHCVSS 8.9EG 8.92026-08-11
Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enab…
- CVE-2026-20728MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a l…
- CVE-2026-20755MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escala…
- CVE-2026-20770MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined…
- CVE-2026-20824MEDIUMCVSS 5.5EG 5.52026-01-13
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-20903MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attac…
- CVE-2026-20906MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low…
- CVE-2026-21387MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may …
- CVE-2026-21400MEDIUMCVSS 5.4EG 5.42026-08-11
Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low comp…
- CVE-2026-21510CRITICALCVSS 8.8EG 9.0⚠ KEV2026-02-10
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21513CRITICALCVSS 8.8EG 9.0⚠ KEV2026-02-10
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21668HIGHCVSS 6.5EG 8.82026-03-12
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
- CVE-2026-21669CRITICALCVSS 9.9EG 9.92026-03-12
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
- CVE-2026-21671CRITICALCVSS 9.1EG 9.12026-03-12
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
- CVE-2026-22013MEDIUMCVSS 5.3EG 5.32026-04-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17…
- CVE-2026-22686CRITICALCVSS 10.0EG 10.02026-01-14
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in …
- CVE-2026-22692MEDIUMCVSS 4.9EG 4.92026-04-14
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the …
- CVE-2026-22707MEDIUMCVSS 5.4EG 5.42026-05-14
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restrictions (`plugin.upload.security.allowed…
- CVE-2026-22709CRITICALCVSS 10.0EG 10.02026-01-26
vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In …
- CVE-2026-22723MEDIUMCVSS 6.5EG 6.52026-03-05
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
- CVE-2026-22753HIGHCVSS 7.5EG 7.52026-04-22
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related securi…
- CVE-2026-23553LOWCVSS 2.9EG 2.92026-01-28
In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between vCPUs, this prevents the guest kernel correctly isolating be…
Map vulnerabilities like CWE-693 to your infrastructure
EchelonGraph correlates every CVE — across CWE-693 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →