Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-602 (服务端安全的客户端实施) — Vulnerability Class 109

109 vulnerabilities classified as CWE-602 (服务端安全的客户端实施). AI Chinese analysis included.

CWE-602 represents a critical architectural flaw where a server improperly delegates security enforcement to the client side. This weakness occurs when developers assume that client-side controls, such as JavaScript validation or UI restrictions, are sufficient to protect sensitive server resources. Attackers typically exploit this by intercepting network traffic or modifying the client application to bypass these checks, allowing them to send unauthorized requests directly to the server. Since the server fails to independently verify the legitimacy of these actions, the attacker can manipulate data, access restricted functions, or cause unexpected system behaviors. To avoid this vulnerability, developers must implement strict server-side validation for all inputs and enforce access controls at the backend. Security mechanisms must never rely on the integrity of the client environment, ensuring that every request is authenticated and authorized regardless of how it was generated.

MITRE CWE Description
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server. When the server relies on protection mechanisms placed on the client side, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.
Common Consequences (2)
Access Control, Availability Bypass Protection Mechanism, DoS: Crash, Exit, or Restart
Client-side validation checks can be easily bypassed, allowing malformed or unexpected input to pass into the application, potentially as trusted data. This may lead to unexpected states, behaviors and possibly a resulting crash.
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
Client-side checks for authentication can be easily bypassed, allowing clients to escalate their access levels and perform unintended actions.
Mitigations (2)
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server. Even though client-side checks provide minim…
Architecture and Design If some degree of trust is required between the two entities, then use integrity checking and strong authentication to ensure that the inputs are coming from a trusted source. Design the product so that this trust is managed in a centralized fashion, especially if there are complex or numerous communication channels, in order to reduce the risks that the implementer will mistakenly omit a check in…
Examples (2)
This example contains client-side code that checks if the user authenticated successfully before sending a command. The server-side code performs the authentication in one step, and executes the command in a separate step.
$server = "server.example.com"; $username = AskForUserName(); $password = AskForPassword(); $address = AskForAddress(); $sock = OpenSocket($server, 1234); writeSocket($sock, "AUTH $username $password\n"); $resp = readSocket($sock); if ($resp eq "success") { # username/pass is valid, go ahead and update the info! writeSocket($sock, "CHANGE-ADDRESS $username $address\n"; } else { print "ERROR: Invalid Authentication!\n"; }
Good · Perl
$sock = acceptSocket(1234); ($cmd, $args) = ParseClientRequest($sock); if ($cmd eq "AUTH") { ($username, $pass) = split(/\s+/, $args, 2); $result = AuthenticateUser($username, $pass); writeSocket($sock, "$result\n"); # does not close the socket on failure; assumes the # user will try again } elsif ($cmd eq "CHANGE-ADDRESS") { if (validateAddress($args)) { $res = UpdateDatabaseRecord($username, "address", $args); writeSocket($sock, "SUCCESS\n"); } else { writeSocket($sock, "FAILURE -- address is malformed\n"); } }
Bad · Perl
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID Title CVSS Severity Published
CVE-2026-100306 TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement — tduck-survey-form 5.3 Medium 2026-09-25
CVE-2026-89175 Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication — EH3040 5.3 Medium 2026-09-11
CVE-2026-84841 tsi-coop tsi-dpdp-cms client-side enforcement of server-side security — tsi-dpdp-cms 7.3 High 2026-09-02
CVE-2026-84110 Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security — Releasit COD Form & Upsells 5.3 Medium 2026-09-01
CVE-2026-73267 Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership check — multicluster engine for Kubernetes 2.10 7.7 High 2026-08-21
CVE-2026-77026 Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 — Convert Forms extension for Joomla 6.9 Medium 2026-08-20
CVE-2026-45274 MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement — talebook 6.9 Medium 2026-08-19
CVE-2026-73627 JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass — jupyterlab 6.0 Medium 2026-08-13
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security — Portal Generator addon to Priority ERP (developed by Soft Solutions) 9.1 Critical 2026-08-13
CVE-2026-16480 IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data. — Db2 4.3 Medium 2026-08-12
CVE-2026-63301 Denial of Service in Quick.CMS — Quick.CMS 7.0 High 2026-07-28
CVE-2026-64813 JetBrains IntelliJ IDEA 处理逻辑错误漏洞 — IntelliJ IDEA 10.0 Critical 2026-07-23
CVE-2026-65051 Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler — Ninja Forms 6.5 Medium 2026-07-21
CVE-2026-13724 Business Logic Bypass in Gobito's Corporate Training Management System — Corporate Training Management System 4.3 Medium 2026-07-20
CVE-2025-36327 Vulnerabilities found in Watson Data Intelligence — watsonx.data intelligence 6.5 Medium 2026-06-30
CVE-2026-57913 Johnson & Johnson Audit Tracking Management System 处理逻辑错误漏洞 — Audit Tracking Management System 7.5 High 2026-06-26
CVE-2026-57912 Johnson & Johnson Campus Recruiting 处理逻辑错误漏洞 — Campus Recruiting 7.5 High 2026-06-26
CVE-2026-56256 Capgo - Two-Factor Authentication Bypass via Organization Management API — Capgo 7.1 High 2026-06-24
CVE-2026-56693 NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action — nanoclaw 5.5 Medium 2026-06-23
CVE-2026-54104 U.S. GAO EPDS and CBCA EDS client-based privilege escalation — Electronic Protest Docketing System (EPDS) 8.8 High 2026-06-18
CVE-2026-42329 Iris has an Open Redirect issue — iris-web 4.7 Medium 2026-06-04
CVE-2026-42160 Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend — dataspace-portal 4.3AI Medium AI 2026-05-08
CVE-2026-39415 Frappe Learning Management System has Client-Side Manipulation of Quiz Scores — lms 7.1AI High AI 2026-04-08
CVE-2026-25737 Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS) — budibase 8.9 High 2026-03-09
CVE-2026-30783 RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies — RustDesk Client 8.8 - 2026-03-05
CVE-2026-23859 Dell Wyse Management Suite WMS 安全漏洞 — Wyse Management Suite 2.7 Low 2026-02-24
CVE-2025-36410 Multiple vulnerabilities found in IBM ApplinX. — ApplinX 3.1 Low 2026-01-20
CVE-2026-0808 Spin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter — Spin Wheel – Interactive spinning wheel that offers coupons 5.3 Medium 2026-01-17
CVE-2026-23478 Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback — cal.com 9.8AI Critical AI 2026-01-13
CVE-2025-14687 Client-Side Enforcement of Server-Side Security in IBM Db2 Intelligence Center — Db2 Intelligence Center 4.3 Medium 2025-12-26

Vulnerabilities classified as CWE-602 (服务端安全的客户端实施) represent 109 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.