← Back
CWE-732

1,702 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

JSON object

Loading...

CVEs (1,702)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maxx
1Waves Maxx Audio
Jun 17, 2026
Aug 16, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
1Arista
1Cloudvision Portal
Nov 21, 2024
Aug 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
1Sap
1Enable Now
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cook...Show more
The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cookie could then be abused to gain access to the application.Show less
1Estsoft
1Altools
Jun 17, 2026
Aug 13, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulne...Show more
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulnerability and execute arbitrary code with system privileges.Show less
1Netwrix
1Auditor
Jun 17, 2026
Aug 12, 2019
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does n...Show more
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the invoking process (in this case, granting Authenticated Users full access over the target file). This vulnerability can be triggered by a low-privileged user to perform DLL Hijacking/Binary Planting attacks and ultimately execute code as NT AUTHORITY\SYSTEM with the help of Symbolic Links.Show less
13cx
13cx
Jun 17, 2026
Aug 12, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a St...Show more
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a StartUp link.Show less
1Cisco
1Adaptive Security Appliance Software
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file w...Show more
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.Show less
1Valvesoftware
1Steam Client
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.
1Pivotal Software
3Application Service
Cloud Foundry UaaOperations Manager
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' an...Show more
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).
1Univa
1Grid Engine
Nov 21, 2024
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
Jul 22, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 155350.
1Akeo
1Rufus
Jun 17, 2026
Jul 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executabl...Show more
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377, CWE-379.Show less