CWE-602

Medium likelihood

Client-Side Enforcement of Server-Side Security

Parent: CWE-693 - Protection Mechanism Failure

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

153 vulnerabilities with CWE-602
CVE-2026-17985 MEDIUM
Google Chrome < 151.0.7922.72 - Site Isolation Bypass via Speech API Policy Enforcement
CVSS 6.5
CVE-2026-17974 MEDIUM
Google Chrome < 151.0.7922.72 - Security Restriction Bypass via DevTools Navigation Policy Enforcement
CVSS 6.5
CVE-2026-17960 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - Referrer Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-17953 MEDIUM
Google Chrome on Android < 151.0.7922.72 - Navigation Restriction Bypass via Crafted HTML Page in WebView
CVSS 6.5
CVE-2026-17703 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-63301 HIGH
Denial of Service in Quick.CMS
CVE-2026-64813 CRITICAL
Jetbrains IntelliJ Idea < 2026.2 - Client-Side Enforcement of Server-Side Security
CVSS 10.0
CVE-2026-65051 MEDIUM
Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler
CVSS 6.5
CVE-2026-13724 MEDIUM
Business Logic Bypass in Gobito's Corporate Training Management System
CVSS 4.3
CVE-2026-46485 HIGH
Dash: Users can write to config despire permissions (OIDC tested)
CVSS 8.2
CVE-2026-15130 MEDIUM
Google Chrome < 150.0.7871.115 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-14109 CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via Mojo Policy Bypass
CVSS 9.6
CVE-2026-14086 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-14081 MEDIUM
Google Chrome < 150.0.7871.47 - Information Disclosure via DevTools Policy Enforcement
CVSS 6.5
CVE-2026-14075 MEDIUM
Google Chrome for iOS < 150.0.7871.47 - No-Referrer Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-14054 MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-14047 MEDIUM
Google Chrome < 150.0.7871.47 - Insufficient Policy Enforcement in Extensions
CVSS 4.3
CVE-2026-14041 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-14036 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-14033 MEDIUM
Google Chrome < 150.0.7871.47 - Insufficient Policy Enforcement in Media
CVSS 6.5
CVE-2026-14007 MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via PermissionsPolicy
CVSS 6.5
CVE-2026-13930 MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13919 MEDIUM
Google Chrome < 150.0.7871.47 - Site Isolation Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13903 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-13901 CRITICAL
Google Chrome - Improper Input Validation
CVSS 9.6
Details
Vulnerabilities 153
Exploit Likelihood Medium