CWE-693: Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
412 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-40536 — SolarWinds Web Help Desk Security Control Bypass Vulnerability
- CVE-2025-0411 — 7-Zip Mark-of-the-Web Bypass Vulnerability
- CVE-2026-33396 — OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
- CVE-2026-23830 — SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-22686 — Sandbox Escape via Host Error Prototype Chain in enclave-vm
- CVE-2025-68668 — n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
- CVE-2026-22709 — vm2 has a Sandbox Escape
- CVE-2025-43728 — Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated
- CVE-2026-25115 — n8n is vulnerable to Python sandbox escape
- CVE-2026-25056 — n8n Arbitrary File Write leading to RCE in n8n Merge Node
- CVE-2025-10157 — PickleScan Bypasses Unsafe Globals Check Using Submodule Imports
- CVE-2025-15618 — Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key
- CVE-2025-41224 — A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All ve
- CVE-2024-5924 — Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability
- CVE-2024-36242 — Protection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enab
- CVE-2025-46358 — Emerson ValveLink Products Protection Mechanism Failure
- CVE-2026-47140 — vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
- CVE-2026-39888 — PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
- CVE-2026-34938 — PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
- CVE-2026-34208 — SandboxJS: Sandbox integrity escape
Recently published
- CVE-2026-79638 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87808 — SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock
- CVE-2026-78552 — Validation Bypass in Okta Access Gateway Custom Directives
- CVE-2026-84811 — agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode
- CVE-2026-84810 — claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan
- CVE-2026-84809 — Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode
- CVE-2026-20277 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-79686 — Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges cou
- CVE-2026-79684 — Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges cou
- CVE-2026-79683 — Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges cou
- CVE-2026-53508 — oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
- CVE-2026-82855 — @hulumi/policies before 1.3.2 Evidence Validation Bypass
- CVE-2026-82474 — Sudo through 1.9.17p2 Intercept Policy Bypass via execveat
- CVE-2026-79988 — Authenticated RCE through Twig sandbox escape
- CVE-2026-61792 — Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)
- CVE-2026-80198 — Kimai before 2.56.0 Information Disclosure via config() Twig Function
- CVE-2026-79006 — Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypas
- CVE-2026-47624 — NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A su
- CVE-2026-79774 — Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy
- CVE-2026-54073 — VeraCrypt: Hidden volume quick format weakens plausible deniability
More specific weaknesses
- CWE-1039 — Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism
- CWE-1248 — Semiconductor Defects in Hardware Logic with Security-Sensitive Implications
- CWE-1253 — Incorrect Selection of Fuse Values
- CWE-1269 — Product Released in Non-Release Configuration
- CWE-1278 — Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques
- CWE-1291 — Public Key Re-Use for Signing both Debug and Production Code
- CWE-1318 — Missing Support for Security Features in On-chip Fabrics or Buses
- CWE-1319 — EM-FI
- CWE-1326 — Missing Immutable Root of Trust in Hardware
- CWE-1338 — Improper Protections Against Hardware Overheating
- CWE-184 — Incomplete List of Disallowed Inputs
- CWE-311 — Missing Encryption of Sensitive Data
- CWE-326 — Inadequate Encryption Strength
- CWE-327 — Use of a Broken or Risky Cryptographic Algorithm
- CWE-330 — Use of Insufficiently Random Values
- CWE-345 — Insufficient Verification of Data Authenticity
- CWE-357 — Insufficient UI Warning of Dangerous Operations
- CWE-602 — Client-Side Enforcement of Server-Side Security
- CWE-757 — Algorithm Downgrade
- CWE-807 — Reliance on Untrusted Inputs in a Security Decision