CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 22 of 38
- CVE-2021-42855HIGHCVSS 7.8EG 7.82022-03-10
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by…
- CVE-2021-42954HIGHCVSS 7.8EG 7.82021-11-17
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user grou…
- CVE-2021-42955HIGHCVSS 7.3EG 7.82021-11-17
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the passwo…
- CVE-2021-43019HIGHCVSS 7.8EG 7.82021-11-23
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and esca…
- CVE-2021-43034HIGHCVSS 7.8EG 7.82021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.
- CVE-2021-43065HIGHCVSS 7.8EG 7.82021-12-09
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.
- CVE-2021-43359HIGHCVSS 8.8EG 8.82021-12-01
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the …
- CVE-2021-43540MEDIUMCVSS 6.5EG 6.52021-12-08
WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95.
- CVE-2021-43998MEDIUMCVSS 6.5EG 6.52021-11-30
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting…
- CVE-2021-44167HIGHCVSS 6.8EG 7.52022-05-11
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive …
- CVE-2021-44230MEDIUMCVSS 6.5EG 6.52021-11-30
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a…
- CVE-2021-44466HIGHCVSS 7.3EG 7.32021-12-30
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs…
- CVE-2021-44512HIGHCVSS 7.0EG 7.02021-12-07
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this …
- CVE-2021-44521CRITICALCVSS 9.1EG 9.12022-02-11
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitra…
- CVE-2021-4480HIGHCVSS 8.2EG 8.22026-06-02
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can rep…
- CVE-2021-4481HIGHCVSS 8.2EG 8.22026-06-02
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can rep…
- CVE-2021-45492HIGHCVSS 7.8EG 7.82022-07-14
In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this directory is writable by unprivileged users b…
- CVE-2021-46561HIGHCVSS 7.2EG 7.22022-01-26
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achie…
- CVE-2021-47742HIGHCVSS 8.8EG 8.82025-12-31
Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files with full access permissions. Attackers can leverage the 'F' (Full) flag for the 'Authenticat…
- CVE-2021-47756HIGHCVSS 8.4EG 8.42026-01-16
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root…
- CVE-2022-0247HIGHCVSS 7.5EG 7.52022-02-25
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed5…
- CVE-2022-0270HIGHCVSS 8.8EG 8.82022-01-25
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.
- CVE-2022-0277MEDIUMCVSS 6.5EG 6.52022-01-20
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
- CVE-2022-0338MEDIUMCVSS 4.3EG 4.32022-01-25
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
- CVE-2022-0483HIGHCVSS 7.8EG 7.82022-02-11
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
- CVE-2022-0532MEDIUMCVSS 4.2EG 4.22022-02-09
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and …
- CVE-2022-0556HIGHCVSS 7.3EG 7.82022-04-11
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.
- CVE-2022-0652HIGHCVSS 3.3EG 7.82022-03-22
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before…
- CVE-2022-0803MEDIUMCVSS 6.5EG 6.52022-04-05
Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2022-1316HIGHCVSS 8.8EG 8.82022-04-11
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation
- CVE-2022-1348MEDIUMCVSS 6.5EG 6.52022-05-25
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, i…
- CVE-2022-1412HIGHCVSS 7.5EG 7.52022-06-13
The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive information like generated passwords.
- CVE-2022-1596MEDIUMCVSS 6.5EG 6.52022-06-21
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected sys…
- CVE-2022-1655MEDIUMCVSS 6.5EG 6.52022-07-22
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental file…
- CVE-2022-20218HIGHCVSS 7.8EG 7.82022-07-13
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i…
- CVE-2022-20234HIGHCVSS 7.5EG 7.52022-07-13
In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a ben…
- CVE-2022-20262LOWCVSS 3.3EG 3.32022-08-12
In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed fo…
- CVE-2022-20274HIGHCVSS 7.8EG 7.82022-08-12
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers…
- CVE-2022-20282HIGHCVSS 7.8EG 7.82022-08-12
In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed f…
- CVE-2022-20284MEDIUMCVSS 5.5EG 5.52022-08-12
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone accounts with User execution privileges needed. User interaction is not needed for exploit…
- CVE-2022-20290MEDIUMCVSS 5.5EG 5.52022-08-12
In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2022-20329HIGHCVSS 7.8EG 7.82022-08-12
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2022-20330LOWCVSS 3.5EG 3.52022-08-12
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interac…
- CVE-2022-20398HIGHCVSS 7.8EG 7.82022-09-13
In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2022-20399MEDIUMCVSS 5.5EG 5.52022-09-13
In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to local information disclosure of network data with no additional execution privileges needed. …
- CVE-2022-21475MEDIUMCVSS 5.9EG 5.92022-04-19
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker w…
- CVE-2022-21694LOWCVSS 3.7EG 3.72022-01-18
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts…
- CVE-2022-21748MEDIUMCVSS 5.5EG 5.52022-06-06
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS0…
- CVE-2022-21749MEDIUMCVSS 5.5EG 5.52022-06-06
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2022-21819HIGHCVSS 7.6EG 7.62022-03-11
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through…
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →