Threats Tagged 'cwe-693'
View all threats tagged with 'cwe-693'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-693'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-17079: CWE-693 Protection Mechanism Failure in IBM Db2 Mirror for iCVE-2026-17079 0 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter. Join the discussion | CVE Database V5 | 08/14/2026, 21:31:34 UTC Added: 08/14/2026, 19:41:46 UTC |
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation BypassCVE-2026-18428 0 Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar deny list via the direct query endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.13 to v3.6 - Fixed: versions 3.7 and 2.19.6 Amazon OpenSearch Service (AWS Managed): - Affected: v2.13 to v3.5 - Fixed: v2.13 to v3.5 (via service software update) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 08/13/2026, 17:46:21 UTC Added: 08/13/2026, 17:53:43 UTC |
CVE-2026-0293: CWE-693 Protection Mechanism Failure in Palo Alto Networks Prisma Access AgentCVE-2026-0293 0 A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected. Join the discussion | CVE Database V5 | 08/13/2026, 01:51:07 UTC Added: 08/13/2026, 02:41:45 UTC |
CVE-2026-69278: CWE-863: Incorrect Authorization in Microsoft Visual Studio CodeCVE-2026-69278 0 Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Join the discussion | CVE Database V5 | 08/11/2026, 17:05:17 UTC Added: 08/11/2026, 17:13:32 UTC |
CVE-2026-62902: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in Microsoft .NET 8.0CVE-2026-62902 0 Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 08/11/2026, 17:04:42 UTC Added: 08/11/2026, 17:13:07 UTC |
CVE-2026-54981: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in Microsoft Python extension for Visual Studio CodeCVE-2026-54981 0 Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. Join the discussion | CVE Database V5 | 08/11/2026, 17:05:41 UTC Added: 08/11/2026, 17:12:25 UTC |
CVE-2026-19152: Inappropriate implementation in Google ChromeCVE-2026-19152 0 Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 08/06/2026, 20:33:48 UTC Added: 08/07/2026, 05:56:49 UTC |
CVE-2026-19168: Inappropriate implementation in Google ChromeCVE-2026-19168 0 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 08/06/2026, 20:33:42 UTC Added: 08/07/2026, 05:56:40 UTC |
CVE-2026-19150: Inappropriate implementation in Google ChromeCVE-2026-19150 0 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 08/06/2026, 20:33:47 UTC Added: 08/07/2026, 05:56:40 UTC |
CVE-2026-13342: CWE-693 Protection Mechanism Failure in Security OptimizerCVE-2026-13342 0 The Security Optimizer WordPress plugin versions 1.5.8 through 1.6.4 contain a vulnerability in the IP-based login restriction feature. This flaw allows unauthenticated requests from IP addresses not on the allowlist to bypass the restriction and access the login form, undermining the intended access control. Join the discussion | CVE Database V5 | 08/06/2026, 17:07:33 UTC Added: 08/06/2026, 22:13:07 UTC |
Showing 1 to 10 of 42 results