CWE-732

High likelihood

Incorrect Permission Assignment for Critical Resource

Parent: CWE-285 - Improper Authorization

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

1,710 vulnerabilities with CWE-732
CVE-2026-47134 MEDIUM
ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy
CVE-2026-49445 CRITICAL
Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVSS 9.2
CVE-2026-15779 MEDIUM
Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation
CVSS 6.1
CVE-2026-53486 CRITICAL
decompress: Archive extraction can create files and links outside the target directory
CVSS 9.1
CVE-2026-62195 HIGH
OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback
CVSS 8.3
CVE-2026-62194 HIGH
OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install
CVSS 8.8
CVE-2026-59148 HIGH
Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
CVSS 8.8
CVE-2026-59946 MEDIUM
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVSS 6.1
CVE-2026-9085 HIGH
DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control
CVSS 8.8
CVE-2026-58424 HIGH
Gitea Open Source Git Server - Permanent Fork PR Workflow Approval Gate Bypass
CVSS 8.9
CVE-2026-44268 MEDIUM
Dell PowerProtect Data Domain - Incorrect Permission Assignment for Critical Resource
CVSS 4.4
CVE-2026-13079 HIGH
WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation
CVSS 7.8
CVE-2026-13769 MEDIUM
Overly permissive File Permissions in AWS CLI
CVSS 5.5
CVE-2026-58174 MEDIUM
Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Session Profile on Import
CVSS 6.5
CVE-2026-43721 MEDIUM
Apple Safari - Denial of Service
CVSS 6.5
CVE-2026-55441 HIGH
mise: Arbitrary command execution via task-include files in an untrusted, config-less repository
CVSS 8.6
CVE-2026-9651 MEDIUM
Schneider Electric EasyLogic T150 (formerly Saitel Dr) Remote Terminal Unit & Controller - Incorrect Permission Assignment for Critical Resource
CVSS 4.4
CVE-2026-32315 MEDIUM
motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVSS 5.5
CVE-2026-54327 LOW
Pi 0.74.0 to < 0.78.1 - auth.json Credential Exposure Race Condition
CVSS 2.2
CVE-2026-12957 HIGH
Arbitrary Code Execution in Language Servers for AWS
CVSS 7.8
CVE-2026-49340 HIGH
Sentriz Gonic < 0.21.0 - Authenticated Arbitrary Playlist File Write
CVSS 8.1
CVE-2026-50267 MEDIUM
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVSS 4.7
CVE-2026-53856 MEDIUM
OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json
CVSS 5.5
CVE-2026-0271 HIGH
Prisma Access Agent: Local Privilege Escalation by Authorized Users
CVSS 7.8
CVE-2026-50570 HIGH
Fission < 1.25.0 PodSpec Validation - CAP_SYS_TIME Privilege Escalation
CVSS 8.5
Details
Vulnerabilities 1,710
Exploit Likelihood High