CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,886 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 25 of 38
- CVE-2022-36122HIGHCVSS 7.8EG 7.82022-10-21
The Automox Agent before 40 on Windows incorrectly sets permissions on key files.
- CVE-2022-36670MEDIUMCVSS 6.7EG 6.72022-09-06
PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted …
- CVE-2022-36687MEDIUMCVSS 6.5EG 6.52022-08-29
Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
- CVE-2022-36800MEDIUMCVSS 4.3EG 4.32022-08-03
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The …
- CVE-2022-37190HIGHCVSS 8.8EG 8.92022-09-13
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
- CVE-2022-37435HIGHCVSS 8.8EG 8.82022-09-01
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
- CVE-2022-37458HIGHCVSS 7.2EG 7.22022-09-02
Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
- CVE-2022-37771MEDIUMCVSS 6.7EG 6.72022-09-06
IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.
- CVE-2022-38065HIGHCVSS 8.8EG 8.82022-12-21
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileg…
- CVE-2022-38103MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access
- CVE-2022-38170MEDIUMCVSS 4.7EG 4.72022-09-02
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and a…
- CVE-2022-38461MEDIUMCVSS 5.4EG 5.42022-11-17
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for…
- CVE-2022-39062HIGHCVSS 7.8EG 7.82023-08-08
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges to replace DLLs and …
- CVE-2022-39186MEDIUMCVSS 6.2EG 6.22023-01-12
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
- CVE-2022-39207MEDIUMCVSS 5.4EG 5.42022-09-13
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. Thes…
- CVE-2022-39284LOWCVSS 2.6EG 2.62022-10-06
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erro…
- CVE-2022-39883HIGHCVSS 4.0EG 7.82022-11-09
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
- CVE-2022-39887MEDIUMCVSS 4.3EG 4.32022-11-09
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
- CVE-2022-40298HIGHCVSS 8.8EG 8.82022-09-23
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair …
- CVE-2022-40756HIGHCVSS 8.8EG 8.82022-09-30
If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/writ…
- CVE-2022-40817MEDIUMCVSS 4.3EG 4.32022-09-27
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related an…
- CVE-2022-41471MEDIUMCVSS 6.5EG 6.52022-10-17
74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.
- CVE-2022-4148MEDIUMCVSS 4.3EG 4.32023-03-20
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
- CVE-2022-41658MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41699HIGHCVSS 8.2EG 8.22023-05-10
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41700MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41766MEDIUMCVSS 4.3EG 4.32023-05-29
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppr…
- CVE-2022-41771MEDIUMCVSS 6.5EG 6.52023-05-10
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-41926LOWCVSS 3.3EG 3.32022-11-25
Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that t…
- CVE-2022-42788MEDIUMCVSS 5.5EG 5.52022-11-01
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious application may be able to read sensitive location information.
- CVE-2022-42949HIGHCVSS 7.5EG 7.52022-12-21
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
- CVE-2022-42972HIGHCVSS 7.8EG 7.82023-02-01
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Softw…
- CVE-2022-43309MEDIUMCVSS 5.5EG 5.52023-04-07
Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.
- CVE-2022-43517HIGHCVSS 7.8EG 7.82022-12-13
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to o…
- CVE-2022-4365MEDIUMCVSS 5.5EG 5.52023-01-12
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry …
- CVE-2022-43773HIGHCVSS 8.8EG 8.82023-04-03
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled.
- CVE-2022-43845LOWCVSS 3.7EG 3.72024-09-25
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from t…
- CVE-2022-43915MEDIUMCVSS 6.8EG 6.82024-08-24
IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with p…
- CVE-2022-43946HIGHCVSS 7.5EG 8.12023-04-11
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.…
- CVE-2022-44216HIGHCVSS 7.5EG 7.52023-02-20
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.
- CVE-2022-44263HIGHCVSS 7.8EG 7.82023-01-26
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.
- CVE-2022-44280MEDIUMCVSS 6.5EG 6.52022-11-23
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.
- CVE-2022-44715HIGHCVSS 8.8EG 8.82023-01-27
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
- CVE-2022-44719HIGHCVSS 7.5EG 7.52023-06-29
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
- CVE-2022-44725HIGHCVSS 7.8EG 7.82022-11-17
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).
- CVE-2022-44732HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
- CVE-2022-44733HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
- CVE-2022-44746MEDIUMCVSS 5.5EG 5.52022-11-07
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
- CVE-2022-45193HIGHCVSS 5.9EG 8.82022-11-12
CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.
- CVE-2022-45301MEDIUMCVSS 4.3EG 4.32022-11-29
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →