CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 36 of 39
- CVE-2025-8042CRITICALCVSS 9.8EG 9.82025-08-19
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.
- CVE-2025-8108MEDIUMCVSS 6.7EG 6.72025-11-11
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of un…
- CVE-2025-8148MEDIUMCVSS 4.2EG 4.22025-12-05
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their S…
- CVE-2025-8886MEDIUMCVSS 6.7EG 6.72025-10-10
Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Privile…
- CVE-2025-9578HIGHCVSS 7.8EG 7.82025-08-28
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40734.
- CVE-2026-0271HIGHCVSS 7.8EG 7.82026-06-10
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS,…
- CVE-2026-0541MEDIUMCVSS 6.7EG 6.72026-05-12
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allo…
- CVE-2026-0775HIGHCVSS 7.0EG 7.02026-01-23
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute l…
- CVE-2026-10591HIGHCVSS 8.8EG 8.82026-06-02
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitiv…
- CVE-2026-10840CRITICALCVSS 7.1EG 9.62026-06-04
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRo…
- CVE-2026-10997MEDIUMCVSS 6.5EG 6.52026-06-04
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromiu…
- CVE-2026-1185MEDIUMCVSS 5.4EG 5.42026-05-12
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis devi…
- CVE-2026-12957HIGHCVSS 7.8EG 7.82026-06-23
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the proje…
- CVE-2026-13079HIGHCVSS 7.8EG 7.82026-07-03
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affec…
- CVE-2026-1344MEDIUMCVSS 5.5EG 6.52026-02-18
Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.
- CVE-2026-13673HIGHCVSS 8.8EG 8.82026-09-18
An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write a…
- CVE-2026-13769MEDIUMCVSS 5.5EG 5.52026-07-01
Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the s…
- CVE-2026-14208HIGHCVSS 7.3EG 7.32026-08-21
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Wi…
- CVE-2026-14478HIGHCVSS 7.8EG 7.82026-08-12
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confid…
- CVE-2026-15430MEDIUMCVSS 6.2EG 6.22026-08-03
Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credential…
- CVE-2026-15779MEDIUMCVSS 6.1EG 6.12026-07-15
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as th…
- CVE-2026-16157HIGHCVSS 7.8EG 7.82026-07-22
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service runnin…
- CVE-2026-18270HIGHCVSS 7.8EG 7.82026-08-20
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must fi…
- CVE-2026-19583CRITICALCVSS 9.9EG 9.92026-09-10
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howeve…
- CVE-2026-20092MEDIUMCVSS 6.0EG 6.02026-01-21
A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate privileges to root on the virtual appliance. This vulnerabil…
- CVE-2026-20693MEDIUMCVSS 4.9EG 4.92026-03-25
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An attacker with root privileges may be able to delete protected system files.
- CVE-2026-21011MEDIUMCVSS 6.8EG 6.82026-04-13
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.
- CVE-2026-21715LOWCVSS 3.3EG 3.32026-03-30
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `…
- CVE-2026-21727LOWCVSS 3.3EG 3.32026-04-15
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user wi…
- CVE-2026-21765HIGHCVSS 8.8EG 8.82026-04-02
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.
- CVE-2026-21902CRITICALCVSS 9.8EG 9.82026-02-25
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. …
- CVE-2026-22280MEDIUMCVSS 5.5EG 5.52026-01-22
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical …
- CVE-2026-2254MEDIUMCVSS 6.3EG 6.32026-05-27
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.
- CVE-2026-22676HIGHCVSS 7.8EG 7.82026-04-15
Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Atta…
- CVE-2026-22768HIGHCVSS 7.3EG 7.32026-04-01
Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- CVE-2026-23648HIGHCVSS 7.8EG 7.82026-02-17
Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local user…
- CVE-2026-24049MEDIUMCVSS 5.5EG 5.52026-01-22
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after ext…
- CVE-2026-24131MEDIUMCVSS 5.5EG 5.52026-01-26
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"director…
- CVE-2026-24291HIGHCVSS 7.8EG 7.82026-03-10
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
- CVE-2026-24732MEDIUMCVSS 6.6EG 6.62026-03-04
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained b…
- CVE-2026-24834HIGHCVSS 8.8EG 8.82026-02-19
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the co…
- CVE-2026-25112HIGHCVSS 7.8EG 7.82026-05-26
A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
- CVE-2026-25770HIGHCVSS 7.2EG 7.22026-03-17
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization…
- CVE-2026-26095MEDIUMCVSS 5.5EG 5.52026-02-20
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.
- CVE-2026-26096MEDIUMCVSS 5.5EG 5.52026-02-20
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.
- CVE-2026-26100MEDIUMCVSS 5.5EG 5.52026-02-20
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.
- CVE-2026-26101HIGHCVSS 7.8EG 7.82026-02-20
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.
- CVE-2026-26102HIGHCVSS 7.8EG 7.82026-02-20
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.
- CVE-2026-2637HIGHCVSS 7.8EG 7.82026-03-03
iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization c…
- CVE-2026-26422HIGHCVSS 8.4EG 8.42026-06-06
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →