CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,966 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 1 of 40
- CVE-2021-23874CRITICALCVSS 8.2EG 9.0⚠ KEV2021-02-10
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
- CVE-2022-22960CRITICALCVSS 7.8EG 9.0⚠ KEV2022-04-13
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
- CVE-2021-36934CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-22
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerabi…
- CVE-2019-15752CRITICALCVSS 7.8EG 9.0⚠ KEV2019-08-28
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an…
- CVE-2018-13374CRITICALCVSS 4.3EG 9.0⚠ KEV2019-01-22
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivi…
- CVE-2026-92941CRITICALCVSS 10.0EG 10.02026-09-17
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and …
- CVE-2026-87988CRITICALCVSS 10.0EG 10.02026-09-11
An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside t…
- CVE-2026-9508CRITICALCVSS 10.0EG 10.02026-05-29
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerabil…
- CVE-2025-14988CRITICALCVSS 10.0EG 10.02026-01-27
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
- CVE-2025-69426CRITICALCVSS 10.0EG 10.02026-01-09
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions…
- CVE-2025-12004CRITICALCVSS 10.0EG 10.02025-10-21
Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: fro…
- CVE-2014-125121CRITICALCVSS 10.0EG 10.02025-07-31
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a star…
- CVE-2020-35949CRITICALCVSS 10.0EG 10.02021-01-01
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by…
- CVE-2026-19583CRITICALCVSS 9.9EG 9.92026-09-10
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howeve…
- CVE-2026-42812CRITICALCVSS 9.9EG 9.92026-05-04
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to wri…
- CVE-2025-46093CRITICALCVSS 9.9EG 9.92025-08-04
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
- CVE-2025-0066CRITICALCVSS 9.9EG 9.92025-01-14
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidential…
- CVE-2024-5618CRITICALCVSS 9.9EG 9.92024-07-18
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: befo…
- CVE-2023-40622CRITICALCVSS 9.9EG 9.92023-09-12
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation…
- CVE-2022-28802CRITICALCVSS 9.9EG 9.92022-09-21
Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Code by Zapier was providing a customer-controlled general-purpose virtual machine that unint…
- CVE-2022-2185CRITICALCVSS 9.9EG 9.92022-07-01
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously …
- CVE-2021-33509CRITICALCVSS 9.9EG 9.92021-05-21
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
- CVE-2020-35948CRITICALCVSS 9.9EG 9.92021-01-01
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote co…
- CVE-2026-66785CRITICALCVSS 2.5EG 9.92026-08-20
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properl…
- CVE-2026-34352CRITICALCVSS 9.8EG 9.82026-03-26
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
- CVE-2026-21902CRITICALCVSS 9.8EG 9.82026-02-25
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. …
- CVE-2025-34212CRITICALCVSS 9.8EG 9.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls an unverified third-party image, downloads …
- CVE-2025-34206CRITICALCVSS 9.8EG 9.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem per…
- CVE-2025-8042CRITICALCVSS 9.8EG 9.82025-08-19
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.
- CVE-2012-10030CRITICALCVSS 9.8EG 9.82025-08-05
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of t…
- CVE-2025-45150CRITICALCVSS 9.8EG 9.82025-08-01
Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.
- CVE-2025-43243CRITICALCVSS 9.8EG 9.82025-07-30
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.
- CVE-2025-25373CRITICALCVSS 9.8EG 9.82025-03-25
The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.
- CVE-2024-53351CRITICALCVSS 9.8EG 9.82025-03-21
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
- CVE-2024-57520CRITICALCVSS 9.8EG 9.82025-02-05
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outsid…
- CVE-2024-41647CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.
- CVE-2024-10018CRITICALCVSS 9.8EG 9.82024-10-16
Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.
- CVE-2024-24117CRITICALCVSS 9.8EG 9.82024-10-02
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
- CVE-2024-6360CRITICALCVSS 9.8EG 9.82024-10-02
Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through …
- CVE-2024-9142CRITICALCVSS 9.8EG 9.82024-09-25
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls. This issue affects e-Belediye: before 2.0…
- CVE-2024-8039CRITICALCVSS 9.8EG 9.82024-09-14
Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.
- CVE-2024-5163CRITICALCVSS 9.8EG 9.82024-06-17
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
- CVE-2024-33435CRITICALCVSS 9.8EG 9.82024-04-29
Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.…
- CVE-2020-36770CRITICALCVSS 9.8EG 9.82024-01-15
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.
- CVE-2023-46141CRITICALCVSS 9.8EG 9.82023-12-14
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
- CVE-2023-0757CRITICALCVSS 9.8EG 9.82023-12-14
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the …
- CVE-2023-6593CRITICALCVSS 9.8EG 9.82023-12-12
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
- CVE-2023-42489CRITICALCVSS 9.8EG 9.82023-10-25
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
- CVE-2023-39004CRITICALCVSS 9.8EG 9.82023-08-09
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to priv…
- CVE-2023-34852CRITICALCVSS 9.8EG 9.82023-06-15
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →