In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juni
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 funct
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th
Permanent Fork PR Workflow Approval Gate Bypass
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users
WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys l
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot
Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalati
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature th
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure fil
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure fil
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role cou
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege
TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable fi
NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with
Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executa
Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network
iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T
Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC)
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an a
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical R
Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gai
Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allo
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti
A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 197 CVE records associated with CWE-732 in our database. Of these, 10 are critical severity, 66 are high severity, and 75 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started