VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 37 of 88
  • CVE-2018-6755HigDec 6, 2018
    risk 0.50cvss 7.2epss 0.01

    Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.

  • CVE-2018-11259HigJul 6, 2018
    risk 0.50cvss 7.7epss 0.00

    Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the…

  • CVE-2018-12457HigJun 15, 2018
    risk 0.50cvss 8.8epss 0.02

    expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.

  • CVE-2026-4761HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are…

  • CVE-2026-32048HigMar 21, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes…

  • CVE-2025-66723HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.00

    inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.

  • CVE-2025-54546HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms, restricted users could use SSH port forwarding to access host-internal services

  • CVE-2025-41664HigSep 8, 2025
    risk 0.49cvss 7.5epss 0.00

    A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e.g., FTP/SFTP). This access could allow the attacker to escalate privileges and modify…

  • CVE-2025-0093HigAug 26, 2025
    risk 0.49cvss 7.5epss 0.00

    In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-30708HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions that are affected are 12.2.4-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-57547HigJan 27, 2025
    risk 0.49cvss 7.5epss 0.01

    Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.

  • CVE-2025-0590HigJan 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.

  • CVE-2024-45497HigDec 31, 2024
    risk 0.49cvss 7.6epss 0.01

    A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from…

  • CVE-2022-30354HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.01

    OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.

  • CVE-2024-44729HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.

  • CVE-2024-8900HigSep 17, 2024
    risk 0.49cvss 7.5epss 0.00

    An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.

  • CVE-2024-7986HigAug 23, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that…

  • CVE-2024-41685HigJul 26, 2024
    risk 0.49cvss 7.5epss 0.01

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on…

  • CVE-2024-29078HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to the product to alter the product settings.

  • CVE-2023-52388HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.