VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 20 of 88
  • CVE-2026-27788HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM…

  • CVE-2026-25112HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.00

    A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

  • CVE-2026-41217HigMay 13, 2026
    risk 0.51cvss 7.9epss 0.00

    A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit…

  • CVE-2026-8110HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

  • CVE-2026-8069HigMay 8, 2026
    risk 0.51cvss 7.8epss 0.00

    PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user…

  • CVE-2026-41288HigMay 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.

  • CVE-2026-22676HigApr 15, 2026
    risk 0.51cvss 7.8epss 0.00

    Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation…

  • CVE-2026-3315HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.

  • CVE-2026-24291HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.03

    Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-29126HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and…

  • CVE-2026-2637HigMar 3, 2026
    risk 0.51cvss 7.8epss 0.00

    iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks. This issue affects iBoysoft…

  • CVE-2026-26102HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

  • CVE-2026-26101HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

  • CVE-2026-23648HigFeb 17, 2026
    risk 0.51cvss 7.8epss 0.00

    Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can…

  • CVE-2019-25344HigFeb 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to…

  • CVE-2019-25343HigFeb 12, 2026
    risk 0.51cvss 7.8epss 0.00

    NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file…

  • CVE-2022-50931HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or…

  • CVE-2025-14979HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.

  • CVE-2025-64699HigDec 31, 2025
    risk 0.51cvss 7.8epss 0.00

    An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to…

  • CVE-2025-13703HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security for PC. An attacker must first obtain the ability to execute…