VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 19 of 88
  • CVE-2025-20387HigDec 3, 2025
    risk 0.52cvss 8.0epss 0.00

    In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets…

  • CVE-2025-20386HigDec 3, 2025
    risk 0.52cvss 8.0epss 0.00

    In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator…

  • CVE-2025-64642HigDec 2, 2025
    risk 0.52cvss 8.0epss 0.00

    NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

  • CVE-2025-20298HigJun 2, 2025
    risk 0.52cvss 8.0epss 0.00

    In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program…

  • CVE-2025-24527HigJan 29, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.

  • CVE-2024-41720HigAug 5, 2024
    risk 0.52cvss 8.0epss 0.00

    Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the configuration of the device.

  • CVE-2023-47564HigFeb 2, 2024
    risk 0.52cvss 8.0epss 0.01

    An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the…

  • CVE-2023-36465CriOct 6, 2023
    risk 0.52cvss 9.1epss 0.01

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to…

  • CVE-2020-5371HigJul 6, 2020
    risk 0.52cvss 8.0epss 0.01

    Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with network or local file access, could take advantage of insufficiently applied file permissions or gain unauthorized access to files.

  • CVE-2019-13321HigFeb 10, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw…

  • CVE-2010-0737HigOct 30, 2019
    risk 0.52cvss 8.0epss 0.01

    A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

  • CVE-2018-13374MedKEVJan 22, 2019
    risk 0.52cvss 4.3epss 0.38

    A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server…

  • CVE-2018-18561HigNov 20, 2018
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Insecure permissions in a service interface may allow authenticated attackers in the adjacent network to execute…

  • CVE-2018-13110HigJul 6, 2018
    risk 0.52cvss 7.5epss 0.06

    All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain access to the command line interface (CLI) if previously disabled by the ISP, escalate their privileges, and perform further attacks.

  • CVE-2017-6104HigMar 2, 2017
    risk 0.52cvss 7.5epss 0.07

    Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

  • CVE-2026-14478HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

  • CVE-2026-63522HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58424HigJul 3, 2026
    risk 0.51cvss 8.9epss 0.00

    Permanent Fork PR Workflow Approval Gate Bypass

  • CVE-2026-13079HigJul 3, 2026
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for…

  • CVE-2026-50209HigJun 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.