← Back
CWE-732

1,702 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

JSON object

Loading...

CVEs (1,702)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Impala
May 13, 2026
Oct 4, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the...Show more
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to point to other Kudu tables. This violates and works around the authorization requirement that creating a Kudu external table via Impala requires an "ALL" privilege at the server scope. This privilege requirement for "CREATE" commands is enforced to precisely avoid this scenario where a malicious user can change the underlying Kudu table mapping. The fix is to enforce the same privilege requirement for "ALTER" commands that would make existing non-external Kudu tables external.Show less
1Schneider Electric
1U.motion Builder
May 13, 2026
Sep 26, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitr...Show more
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.Show less
1Elasticsearch
1Logstash
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to...Show more
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.Show less
1Gstn
1India Goods And Services Tax Network Offline Utility Tool
May 13, 2026
Sep 14, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local us...Show more
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.Show less
1Redhat
1Rhnsd
May 13, 2026
Sep 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
1Advantech
1Webaccess
May 13, 2026
Aug 30, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modifie...Show more
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.Show less
1Kaspersky
1Internet Security
May 13, 2026
Aug 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality...Show more
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.Show less
1Razer
1Synapse
May 13, 2026
Aug 18, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or (2) RazerConfigNativeLOC.dll file.
1Razer
1Synapse
May 13, 2026
Aug 18, 2017
N/A· v4
8.4 HIGH· v3
4.6 MEDIUM· v2
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.
1Microsoft
1Xamarin.ios
May 13, 2026
Aug 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."
1Synology
1Download Station
May 13, 2026
Aug 14, 2017
N/A· v4
7.8 HIGH· v3
6.5 MEDIUM· v2
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an exec...Show more
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.Show less
1Gitlab
1Gitlab
May 13, 2026
Aug 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to o...Show more
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.Show less
1Motorola
1Mx011anm Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet.
1Cisco
1Dpc3939 Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root access to the Network Processor (NP) Linux system by enabling a TELNET da...Show more
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root access to the Network Processor (NP) Linux system by enabling a TELNET daemon (through CVE-2017-9479 exploitation) and then establishing a TELNET session.Show less
1Cisco
1Dpc3939 Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting...Show more
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd server, as demonstrated by copying configuration data into a readable filesystem.Show less
1Statamic
1Statamic
May 13, 2026
Jul 24, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
1Logicaldoc
1Logicaldoc
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.
1Google
1Android
May 13, 2026
Jul 6, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33123882.