Skip to main content

About CWE-693

The consequence is bypass of the protection mechanism, which leaves the asset it guarded exposed.

MITRE marks CWE-693 as DISCOURAGED for mapping real-world vulnerabilities because it is a Pillar; use children or descendants instead.

MITRE name
Protection Mechanism Failure
Abstraction
Pillar: the highest-level weakness, which cannot be made more abstract
Status
Draft

Mitigations

  • +Repeat every client-side security check on the server, because client checks can be removed or bypassed (CWE-602).
  • +Specify which data needs encryption and use well-vetted algorithms for its storage and transmission (CWE-311).
  • +Use multiple simultaneous checks before granting access to critical operations, rather than a single factor (CWE-654).
  • +Map each finding to the specific child entry that names the failed mechanism.

CWE-693 Vulnerabilities

10 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-32202
Windows Shell Spoofing Vulnerability
Microsoft4.34.9%KEV2026-04-14
CVE-2025-40536
SolarWinds Web Help Desk Security Control Bypass Vulnerability
SolarWinds8.173.6%KEV2026-01-28
CVE-2026-21510
Windows Shell Security Feature Bypass Vulnerability
Microsoft8.824.5%KEV2026-02-10
CVE-2026-21513
MSHTML Framework Security Feature Bypass Vulnerability
Microsoft8.815.9%KEV2026-02-10
CVE-2025-0411
7-Zip Mark-of-the-Web Bypass Vulnerability
7-Zip7.067.1%KEV2025-01-25
CVE-2024-38217
Windows Mark of the Web Security Feature Bypass Vulnerability
Microsoft5.410.0%KEV2024-09-10
CVE-2024-38226
Microsoft Publisher Security Feature Bypass Vulnerability
Microsoft7.32.7%KEV2024-09-10
CVE-2024-38213
Windows Mark of the Web Security Feature Bypass Vulnerability
Microsoft6.513.6%KEV2024-08-13
CVE-2024-29988
SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft8.844.9%KEV2024-04-09
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Microsoft8.199.4%KEV2024-02-13

Most Affected Vendors

Frequently Asked Questions

What is CWE-693?→

CWE-693 is a Pillar for protection mechanism failures, where a defense is absent, insufficient or not applied on some path.

Can CWE-693 be used to classify a vulnerability?→

MITRE discourages it because it is extremely high-level. Children or descendants of the entry are recommended instead.

How many exploited vulnerabilities are classified as CWE-693?→

This database lists 10 CVE records mapped to CWE-693 by their CVE Numbering Authority. 10 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-32202, CVE-2025-40536, CVE-2026-21510.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.