CWE-602

Medium likelihood

Client-Side Enforcement of Server-Side Security

Parent: CWE-693 - Protection Mechanism Failure

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

153 vulnerabilities with CWE-602
CVE-2026-13896 MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via Glic Policy Enforcement
CVSS 6.5
CVE-2026-13894 MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13871 MEDIUM
Google Chrome < 150.0.7871.47 - Site Isolation Bypass via GuestView Policy Enforcement
CVSS 6.5
CVE-2026-13795 MEDIUM
Google Chrome for iOS < 150.0.7871.47 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-57913 HIGH
Johnson & Johnson Audit Tracking Management System < 2026-04-21 - Client-Side Enforcement of Server-Side Security
CVSS 7.5
CVE-2026-57912 HIGH
Johnson & Johnson Campus Recruiting < 2025-10-31 - Client-Side Enforcement of Server-Side Security
CVSS 7.5
CVE-2026-56256 HIGH
Capgo - Two-Factor Authentication Bypass via Organization Management API
CVSS 7.1
CVE-2026-56693 MEDIUM
NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action
CVSS 5.5
CVE-2026-54104 HIGH
U.S. GAO EPDS and CBCA EDS client-based privilege escalation
CVSS 8.8
CVE-2026-11287 MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-11267 MEDIUM
Google Chrome < 149.0.7827.53 - Content Security Policy Bypass via Malicious Extension
CVSS 4.3
CVE-2026-11236 HIGH
Google Chrome < 149.0.7827.53 - Sandbox Escape via Web Bluetooth Policy Bypass
CVSS 8.3
CVE-2026-11184 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.3
CVE-2026-11092 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-11062 MEDIUM
Google Chrome < 149.0.7827.53 - Script Injection via Malicious Extension
CVSS 4.3
CVE-2026-11025 MEDIUM
Google Chrome < 149.0.7827.53 - Content Security Policy Bypass via Navigation
CVSS 6.5
CVE-2026-11018 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-11014 MEDIUM
Google Chrome < 149.0.7827.53 - Site Isolation Bypass via Malicious Extension
CVSS 6.5
CVE-2026-11011 HIGH
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Password Manager
CVSS 8.1
CVE-2026-42329 MEDIUM
IRIS <2.4.28 - Open Redirect
CVSS 4.7
CVE-2026-44567 HIGH
Open WebUI: Open WebUI Improper Authorization Control
CVSS 7.3
CVE-2026-42266 HIGH
jupyterlab: Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
CVSS 8.8
CVE-2026-42160 CRITICAL
Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
CVE-2026-5901 MEDIUM
Google Chrome <147.0.7727.55 - Policy Enforcement Bypass
CVSS 6.5
CVE-2026-39415 MEDIUM
Frappe Learning Management System has Client-Side Manipulation of Quiz Scores
CVSS 4.3
Details
Vulnerabilities 153
Exploit Likelihood Medium