Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious a
BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to
iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This serv
MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi
An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3,
On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privil
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i
Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo
BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t
VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability all
An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which run
KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a cra
A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Den
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users).
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission
A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates
On affected platforms, restricted users could use SSH port forwarding to access host-internal services
inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Librar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Network
Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privile
NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker wit
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control confi
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB A
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to per
An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v
A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The
Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and
Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writabl
Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized
A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user cred
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate
Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missi
A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started