CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,886 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 26 of 38
- CVE-2022-45304MEDIUMCVSS 4.3EG 4.32022-11-29
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.
- CVE-2022-45305MEDIUMCVSS 4.3EG 4.32022-11-29
Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.
- CVE-2022-45306MEDIUMCVSS 4.3EG 4.32022-11-29
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
- CVE-2022-45307MEDIUMCVSS 4.3EG 4.32022-11-29
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
- CVE-2022-45552HIGHCVSS 7.5EG 7.52023-03-03
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.
- CVE-2022-4630MEDIUMCVSS 5.3EG 5.32022-12-21
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
- CVE-2022-46338MEDIUMCVSS 6.5EG 6.52022-11-30
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive …
- CVE-2022-46656MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-46792HIGHCVSS 8.8EG 8.82022-12-08
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
- CVE-2022-47927MEDIUMCVSS 5.5EG 5.52023-01-12
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 06…
- CVE-2022-48257MEDIUMCVSS 5.3EG 5.32023-01-13
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
- CVE-2022-50690HIGHCVSS 8.4EG 8.42025-12-22
Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on executable files. Unprivileged local users can replace the ElevationService.exe with a malicious file to execute arbit…
- CVE-2022-50931HIGHCVSS 7.8EG 8.42026-01-13
TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to pot…
- CVE-2023-0207HIGHCVSS 7.5EG 7.52023-04-22
NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.
- CVE-2023-0225MEDIUMCVSS 4.3EG 4.32023-04-03
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
- CVE-2023-0757CRITICALCVSS 9.8EG 9.82023-12-14
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the …
- CVE-2023-0834HIGHCVSS 7.0EG 7.02023-04-28
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 before 8.1.
- CVE-2023-0944MEDIUMCVSS 4.3EG 4.32023-04-05
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not cor…
- CVE-2023-1135HIGHCVSS 7.8EG 7.82023-03-27
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.
- CVE-2023-1516HIGHCVSS 7.9EG 7.92023-03-28
RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a local user to escalate privileges and write files to the RoboDK process and achieve code execution.
- CVE-2023-1692HIGHCVSS 7.5EG 7.52023-05-20
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-1939MEDIUMCVSS 4.3EG 4.32023-04-11
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via …
- CVE-2023-20200HIGHCVSS 7.7EG 7.72023-08-23
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated…
- CVE-2023-20216MEDIUMCVSS 4.4EG 4.42023-08-03
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect imp…
- CVE-2023-20230MEDIUMCVSS 5.4EG 5.42023-08-23
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access…
- CVE-2023-20234MEDIUMCVSS 4.4EG 4.42023-08-23
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because ther…
- CVE-2023-20254HIGHCVSS 7.2EG 7.22023-09-27
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manag…
- CVE-2023-20923MEDIUMCVSS 5.5EG 5.52023-01-26
In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. …
- CVE-2023-21142MEDIUMCVSS 5.5EG 5.52023-06-15
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2023-22294HIGHCVSS 8.8EG 8.82023-04-18
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
- CVE-2023-22326MEDIUMCVSS 4.9EG 4.92023-02-01
In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist …
- CVE-2023-22592HIGHCVSS 4.0EG 7.82023-01-18
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permission settings. IBM X-Force ID: 244073.
- CVE-2023-23610MEDIUMCVSS 6.5EG 6.52023-01-26
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, ev…
- CVE-2023-23939LOWCVSS 3.9EG 3.92023-03-06
Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary crea…
- CVE-2023-24205CRITICALCVSS 9.8EG 9.82023-02-23
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).
- CVE-2023-24626HIGHCVSS 6.5EG 7.82023-04-08
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of…
- CVE-2023-2478CRITICALCVSS 9.6EG 9.62023-05-08
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious u…
- CVE-2023-25150MEDIUMCVSS 5.8EG 5.82023-02-08
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with…
- CVE-2023-25438HIGHCVSS 7.8EG 7.82023-05-04
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.
- CVE-2023-25648MEDIUMCVSS 6.5EG 6.52023-12-14
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
- CVE-2023-25817LOWCVSS 3.5EG 3.52023-03-27
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This is…
- CVE-2023-26427LOWCVSS 3.2EG 3.22023-06-20
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly availabl…
- CVE-2023-27084MEDIUMCVSS 5.3EG 5.32023-03-16
Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController parameter.
- CVE-2023-27095MEDIUMCVSS 6.5EG 6.52023-03-16
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.
- CVE-2023-27096MEDIUMCVSS 6.5EG 6.52023-03-27
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.
- CVE-2023-28068HIGHCVSS 7.3EG 7.32023-05-05
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potentially exploit this vulnerability leading to privilege escalation by writing to a protected…
- CVE-2023-28123MEDIUMCVSS 5.5EG 5.52023-04-19
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.
- CVE-2023-28133HIGHCVSS 7.8EG 7.82023-07-23
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
- CVE-2023-28134HIGHCVSS 7.8EG 7.82023-11-12
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit …
- CVE-2023-28346HIGHCVSS 7.3EG 7.32023-05-31
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being us…
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →