CWE-602: Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
116 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-23478 — Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
- CVE-2025-33025 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-33024 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-32469 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2026-25737 — Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)
- CVE-2025-53969 — Cognex In-Sight Explorer and In-Sight Camera Firmware Client-Side Enforcement of Server-Side Security
- CVE-2024-28029 — Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie
- CVE-2025-9495 — Viessmann Vitogate 300 Authentication Bypass
- CVE-2025-6249 — An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with e
- CVE-2026-64813 — In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- CVE-2026-42160 — Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
- CVE-2025-40591 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2024-42340 — CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
- CVE-2026-72867 — Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)
- CVE-2025-42601 — Captcha Bypass Vulnerability in Meon KYC solutions
- CVE-2025-32808 — W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into t
- CVE-2026-59504 — Priority – CWE-602: Client-Side Enforcement of Server-Side Security
- CVE-2026-30933 — FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info
- CVE-2025-66507 — 1Panel – CAPTCHA Bypass via Client-Controlled Flag
- CVE-2026-42266 — JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
Recently published
- CVE-2026-77999 — Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
- CVE-2026-84841 — tsi-coop tsi-dpdp-cms client-side enforcement of server-side security
- CVE-2026-84110 — Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security
- CVE-2026-73267 — Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership check
- CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5
- CVE-2026-45274 — MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement
- CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-73627 — JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass
- CVE-2026-59504 — Priority – CWE-602: Client-Side Enforcement of Server-Side Security
- CVE-2026-16480 — IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
- CVE-2026-65938 — WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.
- CVE-2026-72867 — Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)
- CVE-2026-63301 — Denial of Service in Quick.CMS
- CVE-2026-64813 — In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- CVE-2026-65051 — Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler
- CVE-2026-13724 — Business Logic Bypass in Gobito's Corporate Training Management System
- CVE-2026-46485 — Dash: Users can write to config despire permissions (OIDC tested)
- CVE-2025-36327 — Vulnerabilities found in Watson Data Intelligence
- CVE-2026-57913 — Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc
- CVE-2026-57912 — Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e