CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,886 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 32 of 38
- CVE-2024-6435HIGHCVSS 8.8EG 8.82024-07-16
A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, a…
- CVE-2024-6510HIGHCVSS 7.8EG 7.82024-09-12
Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.
- CVE-2024-6619HIGHCVSS 8.5EG 8.52024-08-13
In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.
- CVE-2024-6739MEDIUMCVSS 5.3EG 5.32024-07-15
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
- CVE-2024-6780LOWCVSS 3.3EG 3.32024-07-16
Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security risks.
- CVE-2024-6871HIGHCVSS 7.8EG 7.82024-11-22
G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obt…
- CVE-2024-7245HIGHCVSS 7.8EG 7.82024-11-22
Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obt…
- CVE-2024-7513HIGHCVSS 8.8EG 8.82024-08-14
CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated …
- CVE-2024-7572HIGHCVSS 7.1EG 7.12024-12-10
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
- CVE-2024-7594HIGHCVSS 7.5EG 7.52024-09-26
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an a…
- CVE-2024-7612HIGHCVSS 8.8EG 8.82024-10-08
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
- CVE-2024-7986HIGHCVSS 7.5EG 7.52024-08-23
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary…
- CVE-2024-8039CRITICALCVSS 9.8EG 9.82024-09-14
Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.
- CVE-2024-8256MEDIUMCVSS 5.9EG 5.92024-12-10
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user …
- CVE-2024-8540HIGHCVSS 8.8EG 8.82024-12-10
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.
- CVE-2024-8900HIGHCVSS 7.5EG 7.52024-09-17
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
- CVE-2024-9142CRITICALCVSS 9.8EG 9.82024-09-25
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls. This issue affects e-Belediye: before 2.0…
- CVE-2024-9244HIGHCVSS 7.8EG 7.82024-11-22
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must firs…
- CVE-2024-9245HIGHCVSS 7.8EG 7.82024-11-22
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must firs…
- CVE-2024-9842HIGHCVSS 7.3EG 7.32024-11-12
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
- CVE-2025-0064HIGHCVSS 8.7EG 8.72025-02-11
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in …
- CVE-2025-0066CRITICALCVSS 9.9EG 9.92025-01-14
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidential…
- CVE-2025-0093HIGHCVSS 7.5EG 7.52025-08-26
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interacti…
- CVE-2025-0164LOWCVSS 2.3EG 2.32025-09-14
IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment.
- CVE-2025-0374MEDIUMCVSS 6.5EG 6.52025-01-30
When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to fil…
- CVE-2025-0590HIGHCVSS 7.5EG 7.52025-01-20
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.
- CVE-2025-0758MEDIUMCVSS 6.1EG 6.12025-04-16
Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) Description Hitachi Vantara Pentaho Business Analytics Ser…
- CVE-2025-0926MEDIUMCVSS 5.9EG 5.92025-04-23
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patche…
- CVE-2025-10059MEDIUMCVSS 6.5EG 6.52025-09-05
An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions pr…
- CVE-2025-10541HIGHCVSS 7.8EG 7.82025-09-25
iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during s…
- CVE-2025-10643CRITICALCVSS 9.1EG 9.12025-09-17
Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required…
- CVE-2025-1067HIGHCVSS 7.3EG 7.32025-02-25
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim …
- CVE-2025-10751HIGHCVSS 7.8EG 7.82025-10-04
MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects MacForge: 1.2.0 Beta 1.
- CVE-2025-1139MEDIUMCVSS 6.1EG 6.12025-08-20
IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authorization to access due to incorrect permission assignment.
- CVE-2025-11790MEDIUMCVSS 4.4EG 4.42026-03-06
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
- CVE-2025-11906MEDIUMCVSS 6.7EG 6.72025-10-30
A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a user with access to the default flowmon system user account used for SSH access to potent…
- CVE-2025-11921HIGHCVSS 8.5EG 8.52025-11-24
iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
- CVE-2025-12004CRITICALCVSS 10.0EG 10.02025-10-21
Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: fro…
- CVE-2025-12147MEDIUMCVSS 6.0EG 6.02025-10-29
In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclusion rule (e.g., ~field) is applied to a field which contains an object as its value, the …
- CVE-2025-12148MEDIUMCVSS 6.0EG 6.02025-10-29
In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of these fields is properly redacted in the _source document returned by search operations, …
- CVE-2025-12801MEDIUMCVSS 6.5EG 6.52026-03-04
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the …
- CVE-2025-12985HIGHCVSS 8.4EG 8.42026-01-20
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.
- CVE-2025-13703HIGHCVSS 7.8EG 7.82025-12-23
VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security for PC. An attacker mus…
- CVE-2025-13733HIGHCVSS 7.8EG 7.82025-12-12
BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.
- CVE-2025-13941HIGHCVSS 8.8EG 8.82025-12-19
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low …
- CVE-2025-1413HIGHCVSS 8.4EG 8.42025-02-28
DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow…
- CVE-2025-14604HIGHCVSS 7.8EG 7.82026-03-03
IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permissions for resources in a way that allows that resource to be …
- CVE-2025-14740MEDIUMCVSS 6.7EG 6.72026-02-04
Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer creates this directory without proper ownership verificat…
- CVE-2025-14979HIGHCVSS 7.8EG 7.82026-01-06
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.
- CVE-2025-14988CRITICALCVSS 10.0EG 10.02026-01-27
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →