VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 42 of 88
  • CVE-2004-1714HigAug 11, 2004
    risk 0.49cvss 7.1epss 0.01

    BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying…

  • CVE-2001-0006HigFeb 12, 2001
    risk 0.49cvss 7.1epss 0.03

    The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex"…

  • CVE-2026-50570HigJun 10, 2026
    risk 0.48cvss 8.5epss 0.00

    Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety /…

  • CVE-2026-26422HigJun 6, 2026
    risk 0.48cvss 8.4epss 0.00

    clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.

  • CVE-2026-33572HigMar 29, 2026
    risk 0.48cvss 8.4epss 0.00

    OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive information including secrets from tool output.

  • CVE-2026-34352HigMar 26, 2026
    risk 0.48cvss 8.5epss 0.00

    In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

  • CVE-2025-33088HigFeb 17, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.

  • CVE-2024-1486HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

  • CVE-2023-34391HigAug 31, 2023
    risk 0.48cvss 7.4epss 0.00

    Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more…

  • CVE-2023-28346HigMay 31, 2023
    risk 0.48cvss 7.3epss 0.01

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this access. Remote…

  • CVE-2021-27764HigMay 6, 2022
    risk 0.48cvss 7.4epss 0.01

    Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

  • CVE-2021-38475HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.

  • CVE-2021-27070HigMar 11, 2021
    risk 0.48cvss 7.3epss 0.03

    Windows 10 Update Assistant Elevation of Privilege Vulnerability

  • CVE-2020-13912HigJun 7, 2020
    risk 0.48cvss 7.3epss 0.01

    SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.

  • CVE-2020-4347HigApr 16, 2020
    risk 0.48cvss 7.3epss 0.02

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permissions for files used by WebSphere Application Server Network Deployment. IBM X-Force ID: 178412.

  • CVE-2019-12876HigJul 17, 2019
    risk 0.48cvss 7.3epss 0.05

    Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

  • CVE-2019-12270HigMay 21, 2019
    risk 0.48cvss 7.4epss 0.02

    OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group at both the NTFS…

  • CVE-2018-0422HigOct 5, 2018
    risk 0.48cvss 7.3epss 0.01

    A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder…

  • CVE-2026-4757HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.00

    A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.

  • CVE-2026-63358HigJul 21, 2026
    risk 0.47cvss 7.3epss 0.00

    FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their…