CWE-602
Medium likelihoodClient-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
153 vulnerabilities with CWE-602
CVE-2026-13896
MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via Glic Policy Enforcement
CVSS 6.5
CVE-2026-13894
MEDIUM
Google Chrome < 150.0.7871.47 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13871
MEDIUM
Google Chrome < 150.0.7871.47 - Site Isolation Bypass via GuestView Policy Enforcement
CVSS 6.5
CVE-2026-13795
MEDIUM
Google Chrome for iOS < 150.0.7871.47 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-57913
HIGH
Johnson & Johnson Audit Tracking Management System < 2026-04-21 - Client-Side Enforcement of Server-Side Security
CVSS 7.5
CVE-2026-57912
HIGH
Johnson & Johnson Campus Recruiting < 2025-10-31 - Client-Side Enforcement of Server-Side Security
CVSS 7.5
CVE-2026-56256
HIGH
Capgo - Two-Factor Authentication Bypass via Organization Management API
CVSS 7.1
CVE-2026-56693
MEDIUM
NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action
CVSS 5.5
CVE-2026-54104
HIGH
U.S. GAO EPDS and CBCA EDS client-based privilege escalation
CVSS 8.8
CVE-2026-11287
MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-11267
MEDIUM
Google Chrome < 149.0.7827.53 - Content Security Policy Bypass via Malicious Extension
CVSS 4.3
CVE-2026-11236
HIGH
Google Chrome < 149.0.7827.53 - Sandbox Escape via Web Bluetooth Policy Bypass
CVSS 8.3
CVE-2026-11184
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.3
CVE-2026-11092
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-11062
MEDIUM
Google Chrome < 149.0.7827.53 - Script Injection via Malicious Extension
CVSS 4.3
CVE-2026-11025
MEDIUM
Google Chrome < 149.0.7827.53 - Content Security Policy Bypass via Navigation
CVSS 6.5
CVE-2026-11018
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-11014
MEDIUM
Google Chrome < 149.0.7827.53 - Site Isolation Bypass via Malicious Extension
CVSS 6.5
CVE-2026-11011
HIGH
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Password Manager
CVSS 8.1
CVE-2026-42329
MEDIUM
IRIS <2.4.28 - Open Redirect
CVSS 4.7
CVE-2026-44567
HIGH
Open WebUI: Open WebUI Improper Authorization Control
CVSS 7.3
CVE-2026-42266
HIGH
jupyterlab: Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
CVSS 8.8
CVE-2026-42160
CRITICAL
Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
CVE-2026-5901
MEDIUM
Google Chrome <147.0.7727.55 - Policy Enforcement Bypass
CVSS 6.5
CVE-2026-39415
MEDIUM
Frappe Learning Management System has Client-Side Manipulation of Quiz Scores
CVSS 4.3
Details
Vulnerabilities
153
Exploit Likelihood
Medium