VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 60 of 88
  • CVE-2024-28955MedNov 26, 2024
    risk 0.38cvss 5.9epss 0.01

    Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to…

  • CVE-2024-32478MedApr 19, 2024
    risk 0.38cvss 6.9epss 0.00

    Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This allows user 1001 on a multi-user system can replace binary and gain other users' privileges. This vulnerability is fixed in…

  • CVE-2022-45193MedNov 12, 2022
    risk 0.38cvss 5.9epss 0.00

    CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.

  • CVE-2022-26247MedMar 20, 2022
    risk 0.38cvss 5.9epss 0.01

    TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.

  • CVE-2021-27908MedMar 23, 2021
    risk 0.38cvss 5.8epss 0.00

    In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing…

  • CVE-2018-1724MedOct 11, 2018
    risk 0.38cvss 5.9epss 0.00

    IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.

  • CVE-2018-14825MedSep 24, 2018
    risk 0.38cvss 5.8epss 0.01

    On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running Android OS 6.0, CT50 running…

  • CVE-2017-8449MedJun 16, 2017
    risk 0.38cvss 5.9epss 0.01

    X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.

  • CVE-2025-54618MedAug 6, 2025
    risk 0.37cvss 5.7epss 0.00

    Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-27591MedMar 11, 2025
    risk 0.37cvss 6.8epss 0.00

    A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files…

  • CVE-2024-41970MedNov 18, 2024
    risk 0.37cvss 5.7epss 0.00

    A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.

  • CVE-2024-29964MedApr 19, 2024
    risk 0.37cvss 5.7epss 0.01

    Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.

  • CVE-2021-24703MedNov 23, 2021
    risk 0.37cvss 5.7epss 0.00

    The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

  • CVE-2021-30892MedAug 24, 2021
    risk 0.37cvss 5.5epss 0.10

    An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.

  • CVE-2026-68563MedJul 30, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on…

  • CVE-2026-32315MedJun 24, 2026
    risk 0.36cvss 5.5epss 0.01

    motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the…

  • CVE-2025-43290MedMay 26, 2026
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to modify protected parts of the file system.

  • CVE-2026-6369MedApr 20, 2026
    risk 0.36cvss 5.5epss 0.00

    An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain…

  • CVE-2026-4482MedApr 10, 2026
    risk 0.36cvss 5.5epss 0.00

    The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent…

  • CVE-2026-28829MedMar 25, 2026
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.