← Back
CWE-732

1,744 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

JSON object

Loading...

CVEs (1,744)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ca
1Client Automation
May 13, 2026
May 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtai...Show more
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation.Show less
1Cybozu
1Office
May 13, 2026
Apr 28, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
1Tenable
1Nessus
May 13, 2026
Apr 19, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
1Tenable
1Nessus
May 13, 2026
Apr 19, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 13, 2026
Apr 17, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and by...Show more
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.Show less
1Adobe
1Creative Cloud
May 13, 2026
Apr 12, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.
1Nextcloud
1Nextcloud Server
May 13, 2026
Apr 5, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to...Show more
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.Show less
1Nextcloud
1Nextcloud Server
May 13, 2026
Apr 5, 2017
N/A· v4
6.4 MEDIUM· v3
5.5 MEDIUM· v2
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared fil...Show more
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.Show less
1Trendmicro
1Interscan Web Security Virtual Appliance
May 13, 2026
Apr 5, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Acc...Show more
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.Show less
1Riverbed
1Rios
May 13, 2026
Apr 4, 2017
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/t...Show more
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file.Show less
1Solarwinds
1Log And Event Manager
May 13, 2026
Mar 24, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
1Sap
1Gui For Windows
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
1Tenable
1Nessus
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
1Paloaltonetworks
1Terminal Services Agent
May 13, 2026
Mar 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.
1Puppet
1Mcollective Puppet Agent
May 13, 2026
Mar 3, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet...Show more
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.Show less
1Zen Mobile App Native Project
1Zen Mobile App Native
May 13, 2026
Mar 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
1Nvidia
1Gpu Driver
May 13, 2026
Feb 15, 2017
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tamper with the extracted...Show more
All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tamper with the extracted files, potentially leading to escalation of privileges via code execution.Show less
1Nvidia
1Gpu Driver
May 13, 2026
Feb 15, 2017
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service or possible escalation of privileges.
1Google
1Android
May 13, 2026
Feb 8, 2017
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vul...Show more
An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586.Show less
1Google
1Chrome
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unsp...Show more
The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors.Show less