CWE-693: Protection Mechanism Failure

What is CWE-693?

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK6 — A06:2025 — Insecure Design
RELATED CVES (365 DAYS)154
ABSTRACTIONPillar

Vulnerabilities mapped to CWE-693

154 vulnerabilities470.4% increase year over year

Vulnerabilities in CISA KEV for CWE-693

4 vulnerabilities300% increase year over year

Official definition

ByMitre CWE

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Characteristics

Modes of introduction

  • Architecture and Design
  • Implementation
  • Operation

Common consequences

ImpactScopeExplanation
Bypass Protection MechanismAccess Control—
Sources (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan