CWE•Pillar•Draft•20 recent CVEs
CWE-693Protection Mechanism Failure
Description
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.
Common consequences
- Access Control→Bypass Protection Mechanism
Recent CVEs classified under this CWE
CVE-2026-760598.82026-09-10CVE-2026-457707.52026-09-10CVE-2026-03062026-09-10CVE-2026-546949.62026-09-09CVE-2026-796385.32026-09-09CVE-2026-878084.92026-09-09CVE-2026-785526.02026-09-08CVE-2026-498817.82026-09-08CVE-2026-455213.32026-09-08CVE-2026-286687.82026-09-08CVE-2026-286647.82026-09-08CVE-2026-286603.32026-09-08CVE-2026-286587.82026-09-08CVE-2026-286557.82026-09-08CVE-2026-286507.82026-09-08CVE-2026-286427.82026-09-08CVE-2026-286397.82026-09-08CVE-2026-286347.82026-09-08CVE-2026-286274.32026-09-08CVE-2026-286127.82026-09-08