CWE-732
Incorrect Permission Assignment for Critical Resource
Description
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642
CVEs mapped to this weakness (1,752)
page 10 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-35167 | Hig | 0.57 | 8.8 | 0.01 | Aug 19, 2022 | Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions. | ||
| CVE-2021-22648 | Hig | 0.57 | 8.8 | 0.01 | Jul 28, 2022 | Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. | ||
| CVE-2021-38289 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2022 | An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor… | ||
| CVE-2022-30929 | Hig | 0.57 | 8.8 | 0.02 | Jul 6, 2022 | Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper. | ||
| CVE-2022-22941 | Hig | 0.57 | 8.8 | 0.01 | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no… | ||
| CVE-2021-42309 | Hig | 0.57 | 8.8 | 0.03 | Dec 15, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-43359 | Hig | 0.57 | 8.8 | 0.02 | Dec 1, 2021 | Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services. | ||
| CVE-2021-41170 | Cri | 0.57 | 9.8 | 0.02 | Nov 8, 2021 | neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a… | ||
| CVE-2021-3747 | Hig | 0.57 | 8.8 | 0.00 | Oct 1, 2021 | The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner. | ||
| CVE-2021-22149 | Hig | 0.57 | 8.8 | 0.01 | Sep 15, 2021 | Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users. | ||
| CVE-2021-22148 | Hig | 0.57 | 8.8 | 0.01 | Sep 15, 2021 | Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines. | ||
| CVE-2021-35508 | Hig | 0.57 | 8.8 | 0.01 | Sep 1, 2021 | NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service. | ||
| CVE-2020-18121 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2021 | A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. | ||
| CVE-2021-38557 | Hig | 0.57 | 8.8 | 0.02 | Aug 24, 2021 | raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite… | ||
| CVE-2017-16630 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2021 | In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Direct Object Reference (IDOR) in the local user creation function. | ||
| CVE-2021-25318 | Hig | 0.57 | 8.8 | 0.01 | Jul 15, 2021 | A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16. | ||
| CVE-2021-20423 | Hig | 0.57 | 8.8 | 0.01 | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force ID: 196308. | ||
| CVE-2021-31894 | Hig | 0.57 | 8.8 | 0.00 | Jul 13, 2021 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions <… | ||
| CVE-2021-23275 | Hig | 0.57 | 8.8 | 0.00 | Jun 29, 2021 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire… | ||
| CVE-2017-17677 | Hig | 0.57 | 8.8 | 0.01 | May 19, 2021 | BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code. |
- risk 0.57cvss 8.8epss 0.01
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
- risk 0.57cvss 8.8epss 0.01
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
- risk 0.57cvss 8.8epss 0.01
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor…
- risk 0.57cvss 8.8epss 0.02
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no…
- risk 0.57cvss 8.8epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
- risk 0.57cvss 9.8epss 0.02
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a…
- risk 0.57cvss 8.8epss 0.00
The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.
- risk 0.57cvss 8.8epss 0.01
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.
- risk 0.57cvss 8.8epss 0.01
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
- risk 0.57cvss 8.8epss 0.01
NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service.
- risk 0.57cvss 8.8epss 0.01
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
- risk 0.57cvss 8.8epss 0.02
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite…
- risk 0.57cvss 8.8epss 0.01
In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Direct Object Reference (IDOR) in the local user creation function.
- risk 0.57cvss 8.8epss 0.01
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.
- risk 0.57cvss 8.8epss 0.01
IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force ID: 196308.
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions <…
- risk 0.57cvss 8.8epss 0.00
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire…
- risk 0.57cvss 8.8epss 0.01
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.